5.3
CVSSv3

CVE-2019-19805

Published: 30/12/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 up to and including 4.5.3 takes a different amount of time to return depending on whether an email address is configured for the account name provided. This can be used by an malicious user to enumerate accounts by guessing email addresses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mfscripts yetishare