PT-2021-23019 · Unknown · Tiny File Manager
Published
2021-09-15
·
Updated
2025-12-31
·
CVE-2021-40964
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TinyFileManager versions up to and including 2.4.6
Description
A Path Traversal issue exists that allows attackers to upload a file with the
fullpath parameter containing path traversal strings (../ and ..) to escape the server's intended working directory and write malicious files onto any directory on the computer. This can be done with Admin credentials or by exploiting the CSRF vulnerability.Recommendations
For versions up to and including 2.4.6, consider disabling the file upload feature until a patch is available to prevent exploitation of the Path Traversal vulnerability. Restrict access to the
fullpath parameter to minimize the risk of writing malicious files to unintended directories.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tiny File Manager