CVE-2021-40966

MEDIUM

TinyFileManager <=2.4.6 - XSS

Title source: llm
STIX 2.1

Description

A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.

References (2)

Core 2
Core References

Scores

CVSS v3 5.4
EPSS 0.0021
EPSS Percentile 42.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
prasathmani/tiny_file_manager < 2.4.6
Published Sep 15, 2021
Tracked Since Feb 18, 2026