CVE-2021-41976
—CVSS 3.1
5.3 medium
EPSS
1%p62
Published
()
Modified
Description
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.
- Vendors
- tad uploader project
- Products
- tad uploader
- Weakness
- CWE-285, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.