MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2019-12-30T17:00:12
Updated: 2024-08-05T02:25:12.606Z
Reserved: 2019-12-11T00:00:00
Link: CVE-2019-19736

No data.

Status : Modified
Published: 2019-12-30T17:15:20.263
Modified: 2024-11-21T04:35:17.040
Link: CVE-2019-19736

No data.