CVE-2019-16790

HIGH WAF: High
CVSS 8.8 Published: 2019-12-30
CWE-78 CWE-434

In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
Unrestricted File Upload Medium WAF Coverage

OWASP: A04:2021 Insecure Design

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
prasathmanitiny_file_managerup to 2.3.9

References

Back to CVE Database