6.5
CVSSv2

CVE-2019-19734

Published: 30/12/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an malicious user to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mfscripts yetishare