CVE-2021-41567
08.10.2021, 16:15
The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks.
| Vendor | Product | Version |
|---|---|---|
| tad_uploader_project | tad_uploader | 𝑥 < 3.5.4 |
𝑥
= Vulnerable software versions