PT-2020-13035 · Unknown · Tiny File Manager

·

CVE-2020-12103

·

Published

2020-04-28

·

Updated

2025-12-31

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tiny File Manager version 2.4.1
Description The issue allows authenticated users to create backup copies of files with a .bak extension outside the intended scope in the same directory where they are stored. This is due to a vulnerability in the ajax file backup copy functionality.
Recommendations For Tiny File Manager version 2.4.1, consider disabling the ajax file backup copy functionality until a patch is available to prevent exploitation. Restrict access to the backup copy feature to minimize the risk of unauthorized file creation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12103

Affected Products

Tiny File Manager