MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-12-30T17:00:12

Updated: 2024-08-05T02:25:12.606Z

Reserved: 2019-12-11T00:00:00

Link: CVE-2019-19736

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-30T17:15:20.263

Modified: 2024-11-21T04:35:17.040

Link: CVE-2019-19736

cve-icon Redhat

No data.