Show plain JSON{"id": "CVE-2019-20061", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2020-02-10T13:15:11.893", "references": [{"url": "https://medium.com/%40jra8908/yetishare-3-5-2-4-5-4-multiple-vulnerabilities-927d17b71ad", "source": "cve@mitre.org"}, {"url": "https://mfscripts.com/", "tags": ["Product"], "source": "cve@mitre.org"}, {"url": "https://yetishare.com/", "tags": ["Product"], "source": "cve@mitre.org"}, {"url": "https://medium.com/%40jra8908/yetishare-3-5-2-4-5-4-multiple-vulnerabilities-927d17b71ad", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://mfscripts.com/", "tags": ["Product"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://yetishare.com/", "tags": ["Product"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-319"}]}], "descriptions": [{"lang": "en", "value": "The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password."}, {"lang": "es", "value": "El correo electr\u00f3nico de introducci\u00f3n del usuario en MFScripts YetiShare versiones v3.5.2 hasta v4.5.4, puede filtrar la contrase\u00f1a (seleccionada por el sistema) si este correo electr\u00f3nico es enviado en texto sin cifrar. En otras palabras, el usuario no est\u00e1 habilitado para elegir su propia contrase\u00f1a inicial."}], "lastModified": "2024-11-21T04:37:59.613", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:mfscripts:yetishare:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24B6FE06-6620-48FC-9AD3-6E9FA7D2793F", "versionEndIncluding": "4.5.4", "versionStartIncluding": "3.5.2"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}