First published: Fri Nov 25 2022(Updated: )
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.
Credit: help@fluidattacks.com help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tinyfilemanager | =2.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45475 is considered a critical vulnerability due to its ability to allow unauthenticated access to sensitive internal files.
To fix CVE-2022-45475, upgrade Tiny File Manager to a version that addresses the broken access control issue.
CVE-2022-45475 affects users of Tiny File Manager version 2.4.8.
CVE-2022-45475 is characterized as a broken access control vulnerability.
An attacker exploiting CVE-2022-45475 can gain unauthorized access to the application's internal files.