Description
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.
References
https://www.twcert.org.tw/tw/cp-132-5175-a2f8d-1.html
Third Party Advisory
https://www.twcert.org.tw/tw/cp-132-5175-a2f8d-1.html
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
5.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-08T14:15:08.570Z
4 years agoLast modified
2024-11-21T05:27:01.090Z
1 year ago