Vulnerabilities > CVE-2019-20060 - Insecure Storage of Sensitive Information vulnerability in Mfscripts Yetishare

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
mfscripts
CWE-922

Summary

MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.

Common Weakness Enumeration (CWE)