High
CVSS 8.8
Overview
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks.
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on sessio...
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks.
This vulnerability is rated 🟠 HIGH.
Recommended actions: