5
CVSSv2

CVE-2019-19806

Published: 30/12/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 up to and including 4.5.3 displays a message indicating whether an email address is configured for the account name provided. This can be used by an malicious user to enumerate accounts by guessing email addresses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mfscripts yetishare