A path traversal vulnerability exists in TinyFileManager versions up to 2.6, specifically in the POST Parameter Handler function of /filemanager.php. An authenticated attacker can manipulate the file[] argument to traverse directory structures and access unauthorized files on the affected system. This vulnerability affects organizations deploying this open-source file management application. The vulnerability has a CVSS 3.1 score of 5.4 (Medium severity) with a network-based attack vector requiring low complexity and valid user credentials. While the vulnerability does not compromise confidentiality, it enables integrity compromise and availability disruption through unauthorized file access and manipulation. The FAUCET Risk Score of 32.0/100 indicates moderate concern. Exploitation status is elevated due to public disclosure of the vulnerability and available proof-of-concept code, though formal CISA KEV listing has not been assigned. The vendor declined to engage during responsible disclosure efforts. Active community attention combined with public exploit availability suggests this vulnerability warrants prompt patching in any TinyFileManager deployments that cannot be immediately decommissioned or segmented from production environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Prasathmani | TinyFileManager | 2.0, 2.1, 2.2, 2.3, 2.4, 2.5, 2.6CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.