CVE-2021-45010

A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tiny_file_manager_project:tiny_file_manager:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-03-15 12:15

Updated : 2024-02-28 19:09


NVD link : CVE-2021-45010

Mitre link : CVE-2021-45010

CVE.ORG link : CVE-2021-45010


JSON object : View

Products Affected

tiny_file_manager_project

  • tiny_file_manager
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')