Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ifundef

Researcher fromIntruderLabs
#28772of 53,624
8.8Total CVSS
Vulnerabilities · 1
PT-2023-21028
8.8
2023-03-28
Mk-Auth · Mk-Auth · CVE-2023-27246
**Name of the Vulnerable Software and Affected Versions** MK-Auth version 23.01K4.9 **Description** An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth allows attackers to execute arbitrary code via uploading a crafted .htaccess file. **Recommendations** For MK-Auth version 23.01K4.9, consider restricting access to the Virtual Disk to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the Virtual Disk feature to upload files, especially .htaccess files, until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.