Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Johannes Eger

Researcher fromSySS GmbH
#17614of 53,633
15.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-21187
8.8
2021-08-31
Unknown · Mik.Starlight · CVE-2021-36232
**Name of the Vulnerable Software and Affected Versions** MIK.starlight version 7.9.5.24363 **Description** The issue is related to improper authorization in multiple functions, allowing an authenticated attacker to escalate privileges. **Recommendations** For MIK.starlight version 7.9.5.24363, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2021-21188
6.5
2021-08-31
Unknown · Mik.Starlight · CVE-2021-36233
**Name of the Vulnerable Software and Affected Versions** MIK.starlight version 7.9.5.24363 **Description** The issue allows an authenticated attacker to read arbitrary files from the filesystem by specifying the file path, due to the functionality of the `AdminGetFirstFileContentByFilePath` function. **Recommendations** For MIK.starlight version 7.9.5.24363, consider restricting access to the `AdminGetFirstFileContentByFilePath` function to minimize the risk of exploitation.