MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mfscripts yetishare |