CVE-2021-40964
6.5 MEDIUMA Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (wi...
Published: 2021-09-15 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 6.5 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- CWE
- CWE-22
Affected products
| Vendor | Product |
|---|---|
| prasathmani | tiny_file_manager |
Description
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-40964
- [Exploit reference]http://packetstormsecurity.com/files/166330/Tiny-File-Manager-2.4.6-Shell-Upload.html
- [Other]https://gist.github.com/omriinbar/953368dcdd9e5eeefd83920166099528
- [Other]https://github.com/prasathmani/tinyfilemanager
- [Exploit reference]http://packetstormsecurity.com/files/166330/Tiny-File-Manager-2.4.6-Shell-Upload.html
- [Other]https://gist.github.com/omriinbar/953368dcdd9e5eeefd83920166099528
- [Other]https://github.com/prasathmani/tinyfilemanager
Related CVEs
Same vendor
- CVE-2021-40966 — A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that... (5.4 MEDIUM)
- CVE-2021-40965 — A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers t... (8.8 HIGH)
Same CWE
- CVE-2026-48777 — FileBrowser Quantum is a free, self-hosted, web-based file manager
- CVE-2026-8442 — The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8 (8.1 HIGH)
- CVE-2026-49766 — Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions (9.9 CRITICAL)
- CVE-2026-49061 — Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions (7.5 HIGH)
- CVE-2026-40779 — Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions (7.7 HIGH)