First published: Mon Dec 30 2019(Updated: )
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tinyfilemanager | <2.3.9 |
https://github.com/prasathmani/tinyfilemanager/commit/9a499734c5084e3c2eb505f100d50baac1793bd8
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16790 is classified as a high severity vulnerability due to the potential for remote code execution.
CVE-2019-16790 affects only authenticated users of Tiny File Manager prior to version 2.3.9.
To fix CVE-2019-16790, upgrade Tiny File Manager to version 2.3.9 or later.
CVE-2019-16790 is a remote code execution vulnerability.
CVE-2019-16790 allows attackers to exploit file upload from URL and edit/rename files.