go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Tad Honor - Improper Authorization

TVN ID TVN-202109029
CVE ID CVE-2021-41564
CVSS 5.3 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products Tad Honor <= v1.46
Description Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbitrarily without logging in.
Solution Update Tad Honor version to 1.47
Credit Hsuan
Public Date 2021-10-08
Top