CVE Published: 08/10/2021 |
CVE Updated: 17/09/2024 |
CVE Year: 2021 Source: twcert |
Vendor: Tad |
Product: TadTools Status : PUBLISHED
CVE-2021-41566 Description
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H