Vulnerabilities > Dmasoftlab

DATE CVE VULNERABILITY TITLE RISK
2021-04-07 CVE-2021-30147 Cross-Site Request Forgery (CSRF) vulnerability in Dmasoftlab Radius Manager 4.4.0
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
network
low complexity
dmasoftlab CWE-352
8.8
2021-04-02 CVE-2021-29012 Improper Authentication vulnerability in Dmasoftlab DMA Radius Manager 4.4.0
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session.
network
low complexity
dmasoftlab CWE-287
critical
9.8
2021-04-02 CVE-2021-29011 Cross-site Scripting vulnerability in Dmasoftlab DMA Radius Manager 4.4.0
DMA Softlab Radius Manager 4.4.0 is affected by Cross Site Scripting (XSS) via the description, name, or address field (under admin.php).
network
low complexity
dmasoftlab CWE-79
6.1