Project

General

Profile

Actions

Bug #9866

closed

freeradius_view_config.php: File contents are displayed without encoding

Added by Jim Pingle over 4 years ago. Updated over 3 years ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
FreeRADIUS
Target version:
-
Start date:
10/31/2019
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
All
Affected Plus Version:
Affected Architecture:
All

Description

freeradius_view_config.php reads and displays the contents of several FreeRADIUS-related files. The contents are displayed without encoding, which enables potential XSS exploitation.

Actions #1

Updated by Jim Pingle over 4 years ago

  • Status changed from New to Feedback
Actions #2

Updated by Jim Pingle over 4 years ago

  • Private changed from Yes to No
Actions #3

Updated by Max Leighton over 3 years ago

Tested in freeradius3 version 0.15.7_20. I see special characters are being converted as expected. This issue can be marked as resolved.

Actions #4

Updated by Jim Pingle over 3 years ago

  • Status changed from Feedback to Resolved
Actions

Also available in: Atom PDF