CVE-2019-20061

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
10/02/2020
Last modified:
07/11/2023

Description

The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mfscripts:yetishare:*:*:*:*:*:*:*:* 3.5.2 (including) 4.5.4 (including)