Vulnerability Description
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by bruteforcing.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mfscripts | Yetishare | >= 3.5.2, <= 4.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/jra89/CVE-2019-19735ExploitThird Party Advisory
- https://medium.com/%40jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d0
- https://github.com/jra89/CVE-2019-19735ExploitThird Party Advisory
- https://medium.com/%40jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d0
FAQ
What is CVE-2019-19735?
CVE-2019-19735 is a vulnerability with a CVSS score of 9.1 (CRITICAL). class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set th...
How severe is CVE-2019-19735?
CVE-2019-19735 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19735?
Check the references section above for vendor advisories and patch information. Affected products include: Mfscripts Yetishare.