CVE-2021-41974

CRITICAL

Tad Book3 < 3.9 - Unauthenticated Arbitrary Book Content Modification

Title source: llm
STIX 2.1

Description

Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5173-e21ba-1.html

Scores

CVSS v3 9.1
EPSS 0.0122
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-285 CWE-306
Status published
Products (1)
tad_book3_project/tad_book3 < 3.9
Published Oct 08, 2021
Tracked Since Feb 18, 2026