Unrated severityNVD Advisory· Published Dec 30, 2019· Updated Aug 5, 2024
CVE-2019-19735
CVE-2019-19735
Description
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by bruteforcing.
Affected products
2- MFScripts/YetiSharedescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- medium.com/%40jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.