CVE-2021-40964 is a path traversal vulnerability affecting TinyFileManager versions up to and including 2.4.6, allowing authenticated attackers to upload malicious files outside the intended directory. With a CVSS score of 6.5 (Medium), this vulnerability has a high impact on integrity, as it enables unauthorized file writes on the server. While not actively exploited in the wild or on the KEV catalog, a public exploit (EDB-50828) exists, and its FAUCET Risk Score of 90/100 indicates significant potential risk despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.6CPE matchmatch criteria | cpe:2.3:a:prasathmani:tiny_file_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.