CVE-2021-3005
03.01.2021, 04:15
MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.Enginsight
Vendor | Product | Version |
---|---|---|
mk-auth | mk-auth | 𝑥 ≤ 19.01 |
𝑥
= Vulnerable software versions