Описание
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.
Ссылки
- Patch
- Third Party Advisory
- Patch
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.9 (исключая)
cpe:2.3:a:prasathmani:tiny_file_manager:*:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.02173
Низкий
6.5 Medium
CVSS3
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-78
CWE-434
EPSS
Процентиль: 84%
0.02173
Низкий
6.5 Medium
CVSS3
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-78
CWE-434