Vulnerability CVE-2021-40964


Published: 2021-09-15

Description:
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.

See advisories in our WLB2 database:
Topic
Author
Date
High
Tiny File Manager 2.4.6 Shell Upload
Febin Mon Saji
16.03.2022
High
Tiny File Manager 2.4.6 Remote Code Execution (RCE)
FEBIN MON SAJI
07.04.2022

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

 References:
https://gist.github.com/omriinbar/953368dcdd9e5eeefd83920166099528
https://github.com/prasathmani/tinyfilemanager

Copyright 2024, cxsecurity.com

 

Back to Top