Security Advisory
CVE-2019-19736
6.1
MEDIUM
Vulnerability Description
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.
Published Date
December 30, 2019
Official Source
NIST NVD Advisory