CVE-2022-40916

CRITICAL

Tiny File Manager <2.4.7 - Session Fixation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-40916. PoCs published by whitej3rry.

AI-analyzed exploit summary This repository provides a detailed writeup on CVE-2022-40916, a session fixation vulnerability in Tiny File Manager v2.4.7 and below. It includes reproduction steps and verification methods, demonstrating how an attacker can manipulate session cookies to maintain unauthorized access.

Description

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

Exploits (1)

nomisec WRITEUP
by whitej3rry · poc
https://github.com/whitej3rry/CVE-2022-40916

This repository provides a detailed writeup on CVE-2022-40916, a session fixation vulnerability in Tiny File Manager v2.4.7 and below. It includes reproduction steps and verification methods, demonstrating how an attacker can manipulate session cookies to maintain unauthorized access.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Tiny File Manager v2.4.7 and below
Auth required
Prerequisites: Access to intercept and modify HTTP responses · Valid session cookie manipulation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0078
EPSS Percentile 50.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-384
Status published
Products (1)
prasathmani/tiny_file_manager < 2.4.7
Published Feb 06, 2025
Tracked Since Feb 18, 2026