Skip to main content

Vendor/product archive

unit4 / mik.starlight CVEs

Beta · best-effort

4 CVEs tagged to unit4 / mik.starlight0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2021-36234

Published Aug 31, 2021

Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36233

Published Aug 31, 2021

The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36232

Published Aug 31, 2021

Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36231

Published Aug 31, 2021

Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting seriali…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1