VYPR

Mik.starlight

by Unit4

CVEs (4)

  • CVE-2021-36232HigAug 31, 2021
    risk 0.57cvss 8.8epss 0.01

    Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

  • CVE-2021-36231HigAug 31, 2021
    risk 0.57cvss 8.8epss 0.03

    Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.

  • CVE-2021-36233MedAug 31, 2021
    risk 0.42cvss 6.5epss 0.01

    The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.

  • CVE-2021-36234MedAug 31, 2021
    risk 0.36cvss 5.5epss 0.00

    Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.