vendor:
MKPortal
by:
Not mentioned
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: MKPortal
Affected Version From: MKPortal versions prior to 1.1.1
Affected Version To: MKPortal version 1.1.0
Patch Exists: YES
Related CWE: Not mentioned
CPE: a:mkportal:mkportal
Platforms Tested:
2007
Authentication Bypass Vulnerability in MKPortal
MKPortal is prone to an authentication-bypass vulnerability because it fails to restrict access to certain administrative functions. Attackers can exploit this issue to gain unauthorized access to the application.
Mitigation:
Upgrade to MKPortal version 1.1.1 or later.