CVE Published: 08/10/2021 |
CVE Updated: 16/09/2024 |
CVE Year: 2021 Source: twcert |
Vendor: Tad |
Product: TadTools Status : PUBLISHED
CVE-2021-41975 Description
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H