Vulnerability Description
MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mk-Auth | Mk-Auth | <= 19.01 |
References
- http://mk-auth.com.br/Vendor Advisory
- https://gist.github.com/alacerda/3b925cb333eb839ae808d6f01642aeb3Third Party Advisory
- http://mk-auth.com.br/Vendor Advisory
- https://gist.github.com/alacerda/3b925cb333eb839ae808d6f01642aeb3Third Party Advisory
FAQ
What is CVE-2021-3005?
CVE-2021-3005 is a vulnerability with a CVSS score of 4.3 (MEDIUM). MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.
How severe is CVE-2021-3005?
CVE-2021-3005 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3005?
Check the references section above for vendor advisories and patch information. Affected products include: Mk-Auth Mk-Auth.