VulnerabilityModified
CVE-2022-23044
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application.
HIGH 8.8EPSS 0.43%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- prasathmani/tiny file manager
- Source
- help@fluidattacks.com
References
- https://fluidattacks.com/advisories/mosey/Exploit, Third Party Advisory
- https://github.com/prasathmani/tinyfilemanager/Exploit, Issue Tracking, Third Party Advisory
- https://fluidattacks.com/advisories/mosey/Exploit, Third Party Advisory
- https://github.com/prasathmani/tinyfilemanager/Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.