CVE-2022-23044

HIGH

Prasathmani Tiny File Manager - CSRF

Title source: rule
STIX 2.1

Description

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://fluidattacks.com/advisories/mosey/

Scores

CVSS v3 8.8
EPSS 0.0132
EPSS Percentile 79.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (1)
prasathmani/tiny_file_manager 2.4.8
Published Nov 25, 2022
Tracked Since Feb 18, 2026