go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Tad Uploader - Stored XSS

TVN ID TVN-202109032
CVE ID CVE-2021-41567
CVSS 6.1 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products Tad Uploader <= v3.5.3
Description The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks.
Solution Update Tad Uploader version to 3.5.4
Credit Hsuan
Public Date 2021-10-08
Top