A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HPrasathmani Tiny File Manager
APPPrasathmani≤ 2.4.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2022-40916CRITICAL9.8PL ✓same product
Session fixation w Tiny File Manager v2.4.7 i wcześniejszych
CVE-2022-45476CRITICAL9.8PL ✓same product
Niebezpieczne przesyłanie plików w Tiny File Manager umożliwia RCE
CVE-2022-1000CRITICAL9.8PL ✓same product
Path Traversal w Tiny File Manager umożliwia dostęp do plików systemowych
CVE-2022-23044HIGH8.8same product
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform uninten...
CVE-2021-45010HIGH8.8same product
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager be...