Tiny File Manager Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Tiny File Manager versions through 2.4.7. This issue allows attackers to execute arbitrary code by injecting a crafted payload into the name of an uploaded or existing file. The vulnerability arises when the application fails to properly sanitize file names, enabling the execution of malicious scripts in the user's browser.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, upload a file with a name that includes a JavaScript payload. Once the file is uploaded, navigate to the directory where the file is stored. The injected script will execute in the browser, demonstrating the cross-site scripting vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
7.5
exploitability
6.5
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.