CVE-2021-45010
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 70.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 70.08% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- prasathmani/tiny file manager
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/166330/Tiny-File-Manager-2.4.6-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://febin0x4e4a.wordpress.com/2022/01/23/tiny-file-manager-authenticated-rce/Patch, Third Party Advisory
- https://github.com/febinrev/tinyfilemanager-2.4.3-exploit/raw/main/exploit.shExploit, Third Party Advisory
- https://github.com/prasathmani/tinyfilemanager/commit/2046bbde72ed76af0cfdcae082de629bcc4b44c7Patch, Third Party Advisory
- https://github.com/prasathmani/tinyfilemanager/pull/636Patch, Third Party Advisory
- https://github.com/prasathmani/tinyfilemanager/pull/636/files/a93fc321a3c89fdb9bee860bf6df5d89083298d1Patch, Third Party Advisory
- https://raw.githubusercontent.com/febinrev/tinyfilemanager-2.4.6-exploit/main/exploit.shExploit, Third Party Advisory
- https://sploitus.com/exploit?id=1337DAY-ID-37364&utm_source=rss&utm_medium=rssExploit, Third Party Advisory
- http://packetstormsecurity.com/files/166330/Tiny-File-Manager-2.4.6-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://febin0x4e4a.wordpress.com/2022/01/23/tiny-file-manager-authenticated-rce/Patch, Third Party Advisory
- https://github.com/febinrev/tinyfilemanager-2.4.3-exploit/raw/main/exploit.shExploit, Third Party Advisory
- https://github.com/prasathmani/tinyfilemanager/commit/2046bbde72ed76af0cfdcae082de629bcc4b44c7Patch, Third Party Advisory
- https://github.com/prasathmani/tinyfilemanager/pull/636Patch, Third Party Advisory
- https://github.com/prasathmani/tinyfilemanager/pull/636/files/a93fc321a3c89fdb9bee860bf6df5d89083298d1Patch, Third Party Advisory
- https://raw.githubusercontent.com/febinrev/tinyfilemanager-2.4.6-exploit/main/exploit.shExploit, Third Party Advisory
- https://sploitus.com/exploit?id=1337DAY-ID-37364&utm_source=rss&utm_medium=rssExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.