CVE-2021-41975

TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-5174-6f1d5-1.html Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:tadtools_project:tadtools:*:*:*:*:*:*:*:*

Information

Published : 2021-10-08 09:15

Updated : 2022-08-12 09:34


NVD link : CVE-2021-41975

Mitre link : CVE-2021-41975


JSON object : View

CWE
CWE-306

Missing Authentication for Critical Function

Advertisement

dedicated server usa

Products Affected

tadtools_project

  • tadtools