Prasathmani

Tiny File Manager

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 17.04.2026 14:30:12
  • Zuletzt bearbeitet 17.04.2026 15:16:52

A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal. The attack ma...

  • EPSS 0.01%
  • Veröffentlicht 03.02.2026 00:00:00
  • Zuletzt bearbeitet 10.02.2026 20:53:45

Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0....

Exploit
  • EPSS 0.24%
  • Veröffentlicht 28.12.2025 13:32:08
  • Zuletzt bearbeitet 31.12.2025 19:36:39

A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argument fullpath causes path traversal. Remote exploitation of the attack ...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 23.05.2025 00:00:00
  • Zuletzt bearbeitet 31.12.2025 19:43:08

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 06.02.2025 17:15:13
  • Zuletzt bearbeitet 31.12.2025 19:40:50

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 06.02.2025 17:15:13
  • Zuletzt bearbeitet 31.12.2025 19:40:50

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing fil...

Exploit
  • EPSS 0.9%
  • Veröffentlicht 25.11.2022 18:15:11
  • Zuletzt bearbeitet 31.12.2025 19:40:50

Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.

Exploit
  • EPSS 0.92%
  • Veröffentlicht 25.11.2022 18:15:11
  • Zuletzt bearbeitet 31.12.2025 19:40:50

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 25.11.2022 17:15:10
  • Zuletzt bearbeitet 31.12.2025 19:40:50

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 17.03.2022 11:15:07
  • Zuletzt bearbeitet 31.12.2025 19:40:50

Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.