← Back to browse · API

CVE-2021-41566

Severity
CRITICAL
CVSS
9.8
EPSS
0.02007
Risk score
39.9
CISA KEV
No
PoC
No
Published
2021-10-08
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-28582, GHSA-CCV5-PX65-27X6
Products
Tad:TadTools 0 ≤3.2.1
Sources
euvd EUVD-2021-28582

Description

The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.

References