Tiny File Manager
cpe:2.3:a:tiny_file_manager_project:tiny_file_manager:*:*:*:*:*:*:*
- <= 2.4.7
A session fixation vulnerability exists in Tiny File Manager versions through 2.4.7. This issue allows an attacker to manipulate session identifiers, potentially leading to unauthorized actions within the application.
Exploitation of this vulnerability allows for session fixation, where an attacker can set a user's session ID to a known value, potentially leading to unauthorized access or actions within the application.
To reproduce this vulnerability, log into Tiny File Manager. After logging in, intercept the response and modify the session cookie to a 26-character string, such as 'ThisIsDefinatelyIncorectId' or 'aaaaaabbbbbbddddddeeeeeerr'. Then, forward the response to the browser. After modifying the cookie, log out of the file manager. The session ID that was set earlier will still be valid, demonstrating the session fixation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.