← Back

Mk Auth

mk-auth

Vendor: Mk Auth • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mk Auth
1Mk Auth
Feb 18, 2025
Mar 28, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.
1Mk Auth
1Mk Auth
Nov 21, 2024
Jan 4, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.
1Mk Auth
1Mk Auth
Nov 21, 2024
Jan 4, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.
1Mk Auth
1Mk Auth
Nov 21, 2024
Jan 3, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.
1Mk Auth
1Mk Auth
Nov 21, 2024
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts.
1Mk Auth
1Mk Auth
Nov 21, 2024
Jun 29, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MK-AUTH 19.01. XSS vulnerabilities in admin and client scripts allow an attacker to execute arbitrary JavaScript code.
1Mk Auth
1Mk Auth
Nov 21, 2024
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessable credentials to admin/executar_login.php result in admin access.
1Mk Auth
1Mk Auth
Nov 21, 2024
Jun 29, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, pppoe.php, queues.php, and wifi.php.
1Mk Auth
1Mk Auth
Nov 21, 2024
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and gain client privileges via SQL injection in central/executar_login.php.