PT-2022-16016 · Unknown · Daloradius

Lirantal

·

Published

2022-12-06

·

Updated

2022-12-12

·

CVE-2022-23475

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions daloRADIUS versions 1.3 and prior
Description daloRADIUS is an open source RADIUS web management application. It is vulnerable to a combination of cross site scripting (XSS) and cross site request forgery (CSRF) vulnerabilities, which can lead to account takeover in the mng-del.php file due to an unescaped variable reflected in the DOM on line 116.
Recommendations For daloRADIUS versions 1.3 and prior, users are advised to manually apply the commit ec3b4a419e to mitigate this issue. As a temporary workaround, consider mitigating the CSRF vulnerability by making the daloRADIUS session cookie samesite=Lax or by implementing a CSRF token in all forms. Additionally, the XSS vulnerability may be mitigated by escaping it or by introducing a Content-Security policy.

Exploit

Fix

XSS

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-23475
GHSA-C9XX-6MVW-9V84

Affected Products

Daloradius