Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MK-AUTH 跨站脚本漏洞
Vulnerability Description
MK-AUTH是巴西Pedro Filho个人开发者的一套访问控制系统。 MK-AUTH through 19.01 K4.9版本存在跨站脚本漏洞,该漏洞源于管理日志ajax.php的tipo参数。攻击者可利用该漏洞读取centralmka2(会话令牌)cookie。
CVSS Information
N/A
Vulnerability Type
N/A