HIGH🇵🇱 Wersja polska

CVE-2021-45010

CVSS 8.8v3.1pub. 2022-03-15upd. 2025-12-31

A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Prasathmani Tiny File Manager

    APP
    Prasathmani
    ≤ 2.4.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2022-40916CRITICAL9.8PL ✓same product

Session fixation w Tiny File Manager v2.4.7 i wcześniejszych

CVE-2022-45476CRITICAL9.8PL ✓same product

Niebezpieczne przesyłanie plików w Tiny File Manager umożliwia RCE

CVE-2022-1000CRITICAL9.8PL ✓same product

Path Traversal w Tiny File Manager umożliwia dostęp do plików systemowych

CVE-2022-23044HIGH8.8same product

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform uninten...

CVE-2021-40965HIGH8.8same product

A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2....