Vulnerabilities > Mfscripts > Yetishare > 1.03

DATE CVE VULNERABILITY TITLE RISK
2019-12-30 CVE-2019-19734 SQL Injection vulnerability in Mfscripts Yetishare
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.
network
low complexity
mfscripts CWE-89
8.8