Project

General

Profile

Actions

Bug #9866

closed

freeradius_view_config.php: File contents are displayed without encoding

Added by Jim Pingle over 4 years ago. Updated over 3 years ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
FreeRADIUS
Target version:
-
Start date:
10/31/2019
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
All
Affected Plus Version:
Affected Architecture:
All

Description

freeradius_view_config.php reads and displays the contents of several FreeRADIUS-related files. The contents are displayed without encoding, which enables potential XSS exploitation.

Actions

Also available in: Atom PDF