Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-30147. PoCs published by Issac Briones.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in DMA Radius Manager 4.4.0, allowing an attacker to create a new user with specified credentials via a crafted HTML form. The form is auto-submitted using JavaScript, bypassing the need for user interaction.
Description
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in DMA Radius Manager 4.4.0, allowing an attacker to create a new user with specified credentials via a crafted HTML form. The form is auto-submitted using JavaScript, bypassing the need for user interaction.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H