Beveiligingsadvies

CVE-2019-19736

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-12-30 17:00:12
Laatst bijgewerkt 2024-08-05 02:25:12
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.