Junglewise Threat Intelligence

CVE-2023-27753: MK-Auth arbitrary file upload in Fale Conosco component

CVE-2023-27753 · Severity: high · CVSS 8 · Published 2026-05-12

Executive brief

MK-Auth is a management system used by Internet Service Providers (ISPs) to manage client access and permissions. A security flaw in the 'Fale Conosco' support component allows an authenticated user to upload malicious files to the server. If exploited, this allows an attacker to take full control of the system, potentially leading to service disruption or unauthorized access to sensitive ISP management data.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the Central/Suporte/Fale Conosco component of MK-Auth. Authenticated attackers can bypass PHP upload restrictions by appending a specific suffix (e.g., '.phpJunk123png') to their filename, which the server incorrectly validates but still executes as PHP. Although the system prepends a random string to uploaded filenames, the resulting file is stored in the '/mkfiles/' directory. An attacker can achieve Remote Code Execution (RCE) by brute-forcing the filename prefix and accessing the uploaded script via a web request.

Affected products

  • MK-Auth MK-Auth 23.01K4.9 and possibly earlier

Timeline

  • 2026-05-12: disclosed: Initial disclosure date
  • 2026-05-12: advisory: NVD publication date

References

Related threats