CVE-2019-19737
EUVD-2019-933830.12.2019, 17:15
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mfscripts | yetishare | 3.5.2 ≤ 𝑥 ≤ 4.5.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration