Unknown · Tiny File Manager · CVE-2020-12102
**Name of the Vulnerable Software and Affected Versions**
Tiny File Manager version 2.4.1
**Description**
The issue allows authenticated users to enumerate directories and files on the filesystem outside of the application scope due to a Path Traversal vulnerability in the ajax recursive directory listing functionality.
**Recommendations**
For Tiny File Manager version 2.4.1, consider disabling the ajax recursive directory listing functionality until a patch is available to prevent exploitation of the Path Traversal vulnerability.