Mik.starlight
by Unit4
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36232 | Hig | 0.57 | 8.8 | 0.01 | Aug 31, 2021 | Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges. | ||
| CVE-2021-36231 | Hig | 0.57 | 8.8 | 0.03 | Aug 31, 2021 | Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects. | ||
| CVE-2021-36233 | Med | 0.42 | 6.5 | 0.01 | Aug 31, 2021 | The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path. | ||
| CVE-2021-36234 | Med | 0.36 | 5.5 | 0.00 | Aug 31, 2021 | Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors. |
- risk 0.57cvss 8.8epss 0.01
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
- risk 0.57cvss 8.8epss 0.03
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.
- risk 0.42cvss 6.5epss 0.01
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.
- risk 0.36cvss 5.5epss 0.00
Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.