Skip to content

Remote Code Execution

Moderate
prasathmani published GHSA-w72h-v37j-rrwr Dec 29, 2019

Package

tinyfilemanager.php

Affected versions

< 2.3.8

Patched versions

2.3.9

Description

Impact

Remote Code Execution via Upload from URL and Edit/Rename files, only authenticated users will have the impact

Patches

The problem has been patched, users should upgrade to 2.3.9

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2019-16790

Weaknesses

No CWEs