VYPR

MK-Auth

by MK-Auth

CVEs (2)

  • CVE-2023-27753HigMay 12, 2026
    risk 0.52cvss 8.0epss 0.00

    An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-30059MedMay 12, 2026
    risk 0.35cvss 5.4epss 0.00

    An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.