CVE-2021-41564

MEDIUM

Tad Honor < 1.47 - Unauthenticated Authorization Bypass and Arbitrary Article Deletion via Book List Function

Title source: llm
STIX 2.1

Description

Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbitrarily without logging in.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5168-52304-1.html

Scores

CVSS v3 5.3
EPSS 0.0100
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-285
Status published
Products (1)
tad_honor_project/tad_honor < 1.47
Published Oct 08, 2021
Tracked Since Feb 18, 2026