CVE-2021-45010
Summary
| CVE | CVE-2021-45010 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-15 12:15:00 UTC |
| Updated | 2022-03-21 18:56:00 UTC |
| Description | A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tiny File Manager Project | Tiny File Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Tiny File Manager Authenticated RCE | febiNJ | MISC | febin0x4e4a.wordpress.com | |
| Tiny File Manager 2.4.6 Shell Upload ≈ Packet Storm | MISC | packetstormsecurity.com | |
| ???? Exploit Tiny File Manager 2.4.3 Shell Upload Exploit | MISC | sploitus.com | |
| github.com/febinrev/tinyfilemanager-2.4.3-exploit/raw/main/exploit.sh | MISC | github.com | |
| raw.githubusercontent.com/febinrev/tinyfilemanager-2.4.6-exploit/main/exploit.sh | MISC | raw.githubusercontent.com | |
| Patched the RCE bug. by febinrev · Pull Request #636 · prasathmani/tinyfilemanager · GitHub | MISC | github.com | |
| Patched the RCE bug. by febinrev · Pull Request #636 · prasathmani/tinyfilemanager · GitHub | MISC | github.com | |
| Patched the RCE (#636) · prasathmani/tinyfilemanager@2046bbd · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.