ZeroHour

CVE-2021-41566

CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.

Vendors
tadtools project
Products
tadtools
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.