vendor:
Tiny File Manager
by:
FEBIN MON SAJI
6.5
CVSS
MEDIUM
Remote Code Execution (RCE)
78
CWE
Product Name: Tiny File Manager
Affected Version From: Tiny File Manager <= 2.4.6
Affected Version To: Tiny File Manager <= 2.4.6
Patch Exists: YES
Related CWE: CVE-2021-40964
CPE: a:tiny_file_manager:tiny_file_manager
Platforms Tested: Ubuntu 20.04
2022
Tiny File Manager 2.4.6 – Remote Code Execution (RCE)
Tiny File Manager 2.4.6 is vulnerable to Remote Code Execution (RCE) due to a lack of authentication. An attacker can exploit this vulnerability by sending a malicious POST request to the vulnerable application. This will allow the attacker to execute arbitrary code on the server.
Mitigation:
Ensure that authentication is enabled for all applications and that all users have unique, strong passwords.