Tad Uploader是中国台湾Tad个人开发者的一个档案上传管理模组。 Tad Uploader 中存在跨站脚本漏洞,该漏洞源于产品中book list函数的add subject未能正确过滤某些特殊字符。攻击者可通过该漏洞执行客户端代码。以下产品及版本受到影响: Tad Uploader v3.5.3 版本及之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-41566 | 9.8 CRITICAL | Tad TadTools - Arbitrary File Upload |
| CVE-2021-41974 | 9.1 CRITICAL | Tad Book3 - Improper Authorization |
| CVE-2021-41975 | 7.5 HIGH | Tad TadTools - Improper Authorization |
| CVE-2021-41563 | 6.1 MEDIUM | Tad Book3 - Stored XSS |
| CVE-2021-41565 | 6.1 MEDIUM | Tad TadTools - Reflected XSS |
| CVE-2021-41564 | 5.3 MEDIUM | Tad Honor - Improper Authorization |
| CVE-2021-41568 | 5.3 MEDIUM | Tad Web - Improper Authorization |
| CVE-2021-41976 | 5.3 MEDIUM | Tad Uploader - Improper Authorization |
No comments yet