VYPR
Unrated severityNVD Advisory· Published Feb 10, 2020· Updated Aug 5, 2024

CVE-2019-20062

CVE-2019-20062

Description

MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

YetiShare v3.5.2–v4.5.4 allows password reset using a leaked hash that never expires, enabling unauthorized account takeover.

Vulnerability

MFScripts YetiShare versions 3.5.2 through 4.5.4 contain a vulnerability in the password reset functionality. The reset hash, once generated, never expires until it is used. If an attacker obtains this hash (e.g., via a leak or interception), they can reset the associated user's password at any time without needing the original email link or further authentication [1].

Exploitation

An attacker who gains access to a valid password reset hash—whether through database compromise, network sniffing, or other means—can directly use the hash to reset the victim's password. No additional privileges or user interaction beyond obtaining the hash are required.

Impact

Successful exploitation allows the attacker to change the victim's password and take over the account. This leads to unauthorized access to sensitive data stored in the affected YetiShare instance, such as uploaded files and user information, compromising confidentiality, integrity, and availability of user data.

Mitigation

Upgrade to YetiShare version 4.5.5 or later, where the fix enforces an expiration time for password reset hashes. If upgrading is not immediately possible, consider monitoring logs for unusual password reset activity and restricting access to database servers to prevent hash leaks.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.