A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.
Metrics
Affected Vendors & Products
References
History
Wed, 31 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prasathmani
Prasathmani tiny File Manager |
|
| CPEs | cpe:2.3:a:prasathmani:tiny_file_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tinyfilemanager Project
Tinyfilemanager Project tinyfilemanager |
Prasathmani
Prasathmani tiny File Manager |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T02:59:30.871Z
Reserved: 2021-09-13T00:00:00
Link: CVE-2021-40966
No data.
Status : Modified
Published: 2021-09-15T18:15:09.523
Modified: 2025-12-31T19:40:50.980
Link: CVE-2021-40966
No data.