dmasoftlab records
4 published records for vendor dmasoftlab.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-29012No exploit | DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session.dmasoftlab · dma radius manager · CWE-287 | Critical9.8 | — | 3.2% | Apr 2, 2021 |
36Monitor | CVE-2021-30147Proof of concept | DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.dmasoftlab · radius manager · CWE-352 | High8.8 | — | 3.5% | Apr 6, 2021 |
24Monitor | CVE-2021-29011No exploit | DMA Softlab Radius Manager 4.4.0 is affected by Cross Site Scripting (XSS) via the description, name, or address field (under admin.php).dmasoftlab · dma radius manager · CWE-79 | Medium6.1 | — | 1.4% | Apr 2, 2021 |
14Monitor | CVE-2010-4275Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to inject arbitrary wedmasoftlab · radius manager · CWE-79 | Low3.5 | — | 1.3% | Dec 21, 2010 |
- CVE-2021-2901240Plan
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session.
CriticalCVSS 9.8No exploitEPSS 3%dmasoftlab · dma radius managerApr 2, 2021
- CVE-2021-3014736Monitor
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
HighCVSS 8.8Proof of conceptEPSS 4%dmasoftlab · radius managerApr 6, 2021
- CVE-2021-2901124Monitor
DMA Softlab Radius Manager 4.4.0 is affected by Cross Site Scripting (XSS) via the description, name, or address field (under admin.php).
MediumCVSS 6.1No exploitEPSS 1%dmasoftlab · dma radius managerApr 2, 2021
- CVE-2010-427514Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to inject arbitrary we
LowCVSS 3.5Proof of conceptEPSS 1%dmasoftlab · radius managerDec 21, 2010