CVE-2019-20061
Severity CVSS v4.0:
Pending analysis
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
10/02/2020
Last modified:
07/11/2023
Description
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mfscripts:yetishare:*:*:*:*:*:*:*:* | 3.5.2 (including) | 4.5.4 (including) |
To consult the complete list of CPE names with products and versions, see this page



