[GH-ISSUE #555] 🚨 Potential Security Vulnerability #401

Closed
opened 2026-03-02 15:58:29 +03:00 by kerem · 10 comments
Owner
Originally created by @ranjit-git on GitHub (May 23, 2021). Original GitHub issue: https://github.com/prasathmani/tinyfilemanager/issues/555 Hello, @prasathmani - 5 potential high severity security vulnerability in your repository has been disclosed to huntr. Visit report url and validate them [https://www.huntr.dev/bounties/6-other-prasathmani/tinyfilemanager/](https://www.huntr.dev/bounties/6-other-prasathmani/tinyfilemanager/) [https://www.huntr.dev/bounties/7-other-prasathmani/tinyfilemanager/](https://www.huntr.dev/bounties/7-other-prasathmani/tinyfilemanager/) [https://www.huntr.dev/bounties/8-other-prasathmani/tinyfilemanager/](https://www.huntr.dev/bounties/8-other-prasathmani/tinyfilemanager/) [https://www.huntr.dev/bounties/9-other-prasathmani/tinyfilemanager/](https://www.huntr.dev/bounties/9-other-prasathmani/tinyfilemanager/) [https://www.huntr.dev/bounties/10-other-prasathmani/tinyfilemanager/](https://www.huntr.dev/bounties/10-other-prasathmani/tinyfilemanager/)
kerem 2026-03-02 15:58:29 +03:00
  • closed this issue
  • added the
    Security
    label
Author
Owner

@zer0h-bb commented on GitHub (May 25, 2021):

Hi @prasathmani, two other vulnerabilities were found in your repo, please check :

<!-- gh-comment-id:847785785 --> @zer0h-bb commented on GitHub (May 25, 2021): Hi @prasathmani, two other vulnerabilities were found in your repo, please check : - https://huntr.dev/bounties/4-other-prasathmani/tinyfilemanager/ - https://huntr.dev/bounties/5-other-prasathmani/tinyfilemanager/ Best regards,
Author
Owner

@x3rz commented on GitHub (May 30, 2021):

Hello @prasathmani, one more vulnerability was found in your code, visit and do check it.
https://www.huntr.dev/bounties/11-other-prasathmani/tinyfilemanager/

<!-- gh-comment-id:850997605 --> @x3rz commented on GitHub (May 30, 2021): Hello @prasathmani, one more vulnerability was found in your code, visit and do check it. https://www.huntr.dev/bounties/11-other-prasathmani/tinyfilemanager/
Author
Owner

@ranjit-git commented on GitHub (Jan 5, 2022):

Hello, i see it has been 6 month since bug reported and still many of them are not validated .
As fix taking long time so you can validate the report now and when patch is ready then you can confirm the fix also .
Huntr team did not proccessed the bounty to reporter untill it validated.
We invest our time to secure opensource project and report potential security vulnerability to huntr responsively .
If maintainer validate them then reporter gets bounty and it will encourage us to make opensource project a safer place .
Thanks

<!-- gh-comment-id:1005659399 --> @ranjit-git commented on GitHub (Jan 5, 2022): Hello, i see it has been 6 month since bug reported and still many of them are not validated . As fix taking long time so you can validate the report now and when patch is ready then you can confirm the fix also . Huntr team did not proccessed the bounty to reporter untill it validated. We invest our time to secure opensource project and report potential security vulnerability to huntr responsively . If maintainer validate them then reporter gets bounty and it will encourage us to make opensource project a safer place . Thanks
Author
Owner

@michael-milette commented on GitHub (Feb 5, 2022):

Have the security issues reported in CVE-2021-40965 5 months ago been addressed yet?

For more information, please see: https://www.cvedetails.com/cve/CVE-2021-40965/

<!-- gh-comment-id:1030499818 --> @michael-milette commented on GitHub (Feb 5, 2022): Have the security issues reported in CVE-2021-40965 5 months ago been addressed yet? For more information, please see: https://www.cvedetails.com/cve/CVE-2021-40965/
Author
Owner

@prasathmani commented on GitHub (Feb 5, 2022):

not actively contributing now, will fix all this in future release

<!-- gh-comment-id:1030512587 --> @prasathmani commented on GitHub (Feb 5, 2022): not actively contributing now, will fix all this in future release
Author
Owner

@prasathmani commented on GitHub (Feb 12, 2022):

fix to path traversal vulnerability #718. by @joaogmauricio

<!-- gh-comment-id:1037063297 --> @prasathmani commented on GitHub (Feb 12, 2022): fix to path traversal vulnerability #718. by @joaogmauricio
Author
Owner

@ranjit-git commented on GitHub (Feb 12, 2022):

Hello, @prasathmani - 5 potential high severity security vulnerability in your repository has been disclosed to huntr.

Visit report url and validate them https://www.huntr.dev/bounties/6-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/7-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/8-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/9-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/10-other-prasathmani/tinyfilemanager/

@prasathmani
Can you plz validate/invalidate those report in huntr so that huntr can give bounty?

<!-- gh-comment-id:1037067214 --> @ranjit-git commented on GitHub (Feb 12, 2022): > Hello, @prasathmani - 5 potential high severity security vulnerability in your repository has been disclosed to huntr. > > Visit report url and validate them https://www.huntr.dev/bounties/6-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/7-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/8-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/9-other-prasathmani/tinyfilemanager/ https://www.huntr.dev/bounties/10-other-prasathmani/tinyfilemanager/ @prasathmani Can you plz validate/invalidate those report in huntr so that huntr can give bounty?
Author
Owner

@x3rz commented on GitHub (Feb 12, 2022):

Not only these but all mentioned report
thanks

<!-- gh-comment-id:1037182348 --> @x3rz commented on GitHub (Feb 12, 2022): Not only these but all mentioned report thanks
Author
Owner

@prasathmani commented on GitHub (Nov 19, 2022):

This issue is addressed in the new release.

<!-- gh-comment-id:1320960018 --> @prasathmani commented on GitHub (Nov 19, 2022): This issue is addressed in the new [release](https://github.com/prasathmani/tinyfilemanager/releases/tag/2.5.0).
Author
Owner

@michael-milette commented on GitHub (Nov 21, 2022):

Thank you @prasathmani !

<!-- gh-comment-id:1322420158 --> @michael-milette commented on GitHub (Nov 21, 2022): Thank you @prasathmani !
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tinyfilemanager#401
No description provided.