Description
TadTools special page parameter does not properly restrict the input of specific characters, thus remote attackers can inject JavaScript syntax without logging in, and further perform reflective XSS attacks.
No analysis available yet.
Remediation
Vendor Solution
Update TadTools version to 3.2.2
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28581 | TadTools special page parameter does not properly restrict the input of specific characters, thus remote attackers can inject JavaScript syntax without logging in, and further perform reflective XSS attacks. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5169-327ef-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:13:39.371Z
Reserved: 2021-09-22T00:00:00.000Z
Link: CVE-2021-41565
No data.
Status : Modified
Published: 2021-10-08T16:15:07.890
Modified: 2024-11-21T06:26:26.357
Link: CVE-2021-41565
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD