Lucene search

K

Daloradius Security Vulnerabilities

cve
cve

CVE-2022-23475

daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped variable reflected ...

8.8CVSS

8.3AI Score

0.001EPSS

2022-12-06 08:15 PM
31
cve
cve

CVE-2022-4366

Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.

7.5CVSS

7.5AI Score

0.001EPSS

2022-12-08 07:15 PM
28
cve
cve

CVE-2022-4630

Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.

5.3CVSS

5.3AI Score

0.001EPSS

2022-12-21 06:15 PM
26
cve
cve

CVE-2023-0046

Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch.

7.2CVSS

7AI Score

0.001EPSS

2023-01-04 12:15 PM
29
cve
cve

CVE-2023-0048

Code Injection in GitHub repository lirantal/daloradius prior to master-branch.

8.8CVSS

7.6AI Score

0.001EPSS

2023-01-04 02:15 PM
39
cve
cve

CVE-2023-0337

Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.

6.1CVSS

5.7AI Score

0.001EPSS

2023-01-17 04:15 PM
32
cve
cve

CVE-2023-0338

Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.

6.1CVSS

5.7AI Score

0.001EPSS

2023-01-17 04:15 PM
20