go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Tad Book3 - Improper Authorization

TVN ID TVN-202109036
CVE ID CVE-2021-41974
CVSS 9.1 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products Tad Book3 <= v3.89
Description Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.
Solution Update Tad Book3 version to 3.9
Credit Hsuan
Public Date 2021-10-08
Top