Description
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9337 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:25:12.606Z
Reserved: 2019-12-11T00:00:00.000Z
Link: CVE-2019-19736
No data.
Status : Modified
Published: 2019-12-30T17:15:20.263
Modified: 2024-11-21T04:35:17.040
Link: CVE-2019-19736
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD