← Back

CVE-2019-19805

nvd nist
Published: Dec 30, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

Affected (1)

Products: Mfscripts: Yetishare
1 product
Yetishare
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 3.5.2 to 4.5.3

Timeline

No history available yet.