PT-2022-12280 · Taocms · Taocms

7Wkajko

·

Published

2022-02-04

·

Updated

2022-02-08

·

CVE-2021-44983

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions taocms version 3.0.1
Description The issue is related to an Arbitrary file download vulnerability. It occurs after logging in to the background, specifically at the File Management column.
Recommendations For taocms version 3.0.1, consider restricting access to the File Management column to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44983

Affected Products

Taocms