ZeroHour

CVE-2020-12103

CVSS 3.1
7.7 high
EPSS
1%p72
Published
()
Modified
Description

In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.

Vendors
prasathmani
Products
tiny file manager
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.