Lucene search

K
cvelistMitreCVELIST:CVE-2019-19806
HistoryDec 30, 2019 - 5:07 p.m.

CVE-2019-19806

2019-12-3017:07:08
mitre
www.cve.org
4

EPSS

0.001

Percentile

35.9%

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

EPSS

0.001

Percentile

35.9%

Related for CVELIST:CVE-2019-19806