Description
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-8767 | MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T18:16:22.470Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21494
No data.
Status : Modified
Published: 2021-01-04T03:15:13.387
Modified: 2024-11-21T05:48:29.210
Link: CVE-2021-21494
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD