mirror of
https://github.com/prasathmani/tinyfilemanager.git
synced 2026-04-26 19:05:54 +03:00
[GH-ISSUE #715] What about CVE-2021-40965 (CSRF vulnerability)? #496
Labels
No labels
Feature
Feature
Is It Really an Issue?
Need More Info
Request
Security
bug
duplicate
enhancement
enhancement
help wanted
invalid
pull-request
question
suggestion
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/tinyfilemanager#496
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @rdggithub on GitHub (Feb 6, 2022).
Original GitHub issue: https://github.com/prasathmani/tinyfilemanager/issues/715
There is a CSRF vulnerability reported in 2.4.6 since 09/2021? Also XSS and path traversal?!
https://cve.report/CVE-2021-40965
https://cve.report/CVE-2021-40966
https://cve.report/CVE-2021-40964
Also the releases on
https://github.com/prasathmani/tinyfilemanager/releases
do not include the versions from 2.4.4 to 2.4.6?!
@prasathmani commented on GitHub (Feb 12, 2022):
fixed path traversal vulnerability #718, by @joaogmauricio