Mk Auth is a narrowly scoped authentication or authorization product that punches above its volume in the vulnerability landscape, suggesting meaningful deployment or security relevance despite a small CVE footprint. The recurring exposure centers on the single product line itself, with weakness patterns not yet showing a durable signature. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mk Auth over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14072CRITICAL An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts. | Jun 29, 2020 | 9.8 | 33 | NO | NO |
CVE-2020-14068CRITICAL An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and gain client privileges via SQL injection in central/executar_l | Jun 29, 2020 | 9.8 | 30 | NO | NO |
CVE-2023-27246HIGH An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file. | Mar 28, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-21495HIGH MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI. | Jan 4, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-14070CRITICAL An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessable credentials to admin/executar_login.php result in admin ac | Jun 29, 2020 | 9.8 | 26 | NO | NO |
CVE-2021-21494MEDIUM MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to | Jan 4, 2021 | 4.8 | 19 | NO | NO |
CVE-2021-3005MEDIUM MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php U | Jan 3, 2021 | 4.3 | 18 | NO | NO |
CVE-2020-14069MEDIUM An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, p | Jun 29, 2020 | 6.8 | 18 | NO | NO |
CVE-2020-14071MEDIUM An issue was discovered in MK-AUTH 19.01. XSS vulnerabilities in admin and client scripts allow an attacker to execute arbitrary JavaScript code. | Jun 29, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mk Auth.
Media articles that mention a CVE ID that affects a product developed by Mk Auth — matched by CVE ID, not by vendor name.