Description
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28118 | A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer. |
References
History
Wed, 31 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prasathmani
Prasathmani tiny File Manager |
|
| CPEs | cpe:2.3:a:prasathmani:tiny_file_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tinyfilemanager Project
Tinyfilemanager Project tinyfilemanager |
Prasathmani
Prasathmani tiny File Manager |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T02:59:30.328Z
Reserved: 2021-09-13T00:00:00.000Z
Link: CVE-2021-40964
No data.
Status : Modified
Published: 2021-09-15T18:15:09.413
Modified: 2025-12-31T19:40:50.980
Link: CVE-2021-40964
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD