MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-12-30T17:00:12
Updated: 2024-08-05T02:25:12.606Z
Reserved: 2019-12-11T00:00:00
Link: CVE-2019-19736
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-12-30T17:15:20.263
Modified: 2024-11-21T04:35:17.040
Link: CVE-2019-19736
Redhat
No data.