MK-AUTH through 19.01 K4.9 allows XSS via the admin...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jan 4, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.
References