PT-2021-14560 · Mk-Auth · Mk-Auth
Alacerda
+3
·
Published
2021-01-04
·
Updated
2022-05-03
·
CVE-2021-21494
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MK-AUTH versions through 19.01 K4.9
Description
The issue allows for XSS via the "admin/logs ajax.php" endpoint, specifically through the
tipo parameter. An attacker can exploit this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.Recommendations
For MK-AUTH versions through 19.01 K4.9, consider restricting access to the "admin/logs ajax.php" endpoint until a patch is available. As a temporary workaround, avoid using the
tipo parameter in the affected endpoint to minimize the risk of exploitation.Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mk-Auth