Medium severity4.3NVD Advisory· Published Jan 3, 2021· Updated Jun 17, 2026
CVE-2021-3005
CVE-2021-3005
Description
MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- MK-AUTH/MK-AUTHdescription
Patches
Vulnerability mechanics
References
2- mk-auth.com.brnvdVendor Advisory
- gist.github.com/alacerda/3b925cb333eb839ae808d6f01642aeb3nvdThird Party Advisory
News mentions
0No linked articles in our index yet.