First published: Fri Oct 08 2021(Updated: )
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
Credit: twcert@cert.org.tw twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Array-tools | <3.2.2 |
Update TadTools version to 3.2.2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41566 has a high severity rating due to its potential for remote code execution by attackers.
To fix CVE-2021-41566, upgrade TadTools to version 3.2.2 or later where the file upload vulnerability has been patched.
Due to CVE-2021-41566, attackers can upload any type of files since the file extension filtering is inadequate.
The potential impacts of CVE-2021-41566 include arbitrary code execution and unauthorized access to the affected system.
No, CVE-2021-41566 allows remote attackers to exploit the vulnerability without the need for authentication.