CVE-2022-23044

HIGH

Tiny File Manager 2.4.8 - Unauthenticated Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://fluidattacks.com/advisories/mosey/

Scores

CVSS v3 8.8
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (1)
prasathmani/tiny_file_manager 2.4.8
Published Nov 25, 2022
Tracked Since Feb 18, 2026