A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-09-15T17:10:32
Updated: 2024-08-04T02:59:30.871Z
Reserved: 2021-09-13T00:00:00
Link: CVE-2021-40966
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-15T18:15:09.523
Modified: 2024-11-21T06:25:09.790
Link: CVE-2021-40966
Redhat
No data.