Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-5175-a2f8d-1.html Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: twcert

Published: 2021-10-08T00:00:00

Updated: 2021-10-08T15:15:43

Reserved: 2021-10-04T00:00:00


Link: CVE-2021-41976

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-08T16:15:08.570

Modified: 2022-08-12T16:30:16.993


Link: CVE-2021-41976

JSON object: View

cve-icon Redhat Information

No data.