Dec. 6, 2022, 8:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped variable reflected in the DOM on line 116. This issue has been addressed in commit `ec3b4a419e`. Users are advised to manually apply the commit in order to mitigate this issue. Users may also mitigate this issue with in …

cve daloradius

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior Manager - Vendor management/ Compliance

@ Sprinklr | India - Haryana - Gurgaon

DevSecOps Engineer

@ Swiss Re | Hyderabad, TG, IN

Cyber Security Architect

@ Endeavour Group | Surry Hills, Australia

Principal Product Manager (Network/Security Management) - NetSec

@ Palo Alto Networks | Bengaluru, India

Lead Security Analyst

@ Deloitte | Sydney, NSW, AU