CVE-2021-3005 Information
Jun 07, 2022
cve
Description
MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g. a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://gist.github.com/alacerda/3b925cb333eb839ae808d6f01642aeb3 http://mk-auth.com.br/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: