First published: Fri Oct 08 2021(Updated: )
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
Credit: twcert@cert.org.tw twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Array-tools | <3.2.2 |
Update TadTools version to 3.2.2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41975 has been identified as a high severity vulnerability due to its potential for unauthorized file deletion.
To mitigate CVE-2021-41975, upgrade TadTools to version 3.2.2 or later.
CVE-2021-41975 is an authorization bypass vulnerability that allows remote attackers to delete arbitrary files.
CVE-2021-41975 affects users of TadTools versions prior to 3.2.2.
Yes, CVE-2021-41975 can be exploited remotely by attackers without the need for authentication.