A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HPrasathmani Tiny File Manager
APPPrasathmani≤ 2.4.7
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEPath Traversal
CWE
Referencje
Powiązane podatności
CVE-2022-40916CRITICAL9.8PL ✓ten sam produkt
Session fixation w Tiny File Manager v2.4.7 i wcześniejszych
CVE-2022-45476CRITICAL9.8PL ✓ten sam produkt
Niebezpieczne przesyłanie plików w Tiny File Manager umożliwia RCE
CVE-2022-1000CRITICAL9.8PL ✓ten sam produkt
Path Traversal w Tiny File Manager umożliwia dostęp do plików systemowych
CVE-2022-23044HIGH8.8ten sam produkt
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform uninten...
CVE-2021-40965HIGH8.8ten sam produkt
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2....