Vulnerability Description
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mk-Auth | Mk-Auth | <= 19.01 |
Related Weaknesses (CWE)
References
- http://mk-auth.com.br/Vendor Advisory
- https://gist.github.com/alacerda/380b8923e36a29a02ba1457c1eb3ec2fExploitThird Party Advisory
- http://mk-auth.com.br/Vendor Advisory
- https://gist.github.com/alacerda/380b8923e36a29a02ba1457c1eb3ec2fExploitThird Party Advisory
FAQ
What is CVE-2021-21494?
CVE-2021-21494 is a vulnerability with a CVSS score of 4.8 (MEDIUM). MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.
How severe is CVE-2021-21494?
CVE-2021-21494 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21494?
Check the references section above for vendor advisories and patch information. Affected products include: Mk-Auth Mk-Auth.