#VU49221 OS Command Injection in Mk-Auth - CVE-2020-14072
Published: June 29, 2020 / Updated: January 4, 2021
Mk-Auth
Mk-Auth
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the /auth admin scripts. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system with root privileges.