CVE-2021-41976

MEDIUM

tad_uploader < 3.5.4 - Unauthenticated Authorization Bypass in Edit Book List Function

Title source: llm
STIX 2.1

Description

Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5175-a2f8d-1.html

Scores

CVSS v3 5.3
EPSS 0.0100
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-285 CWE-306
Status published
Products (1)
tad_uploader_project/tad_uploader < 3.5.4
Published Oct 08, 2021
Tracked Since Feb 18, 2026