Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Peefour

#17431of 53,625
15.4Total CVSS
Vulnerabilities · 2
High
2
PT-2020-13034
7.7
2020-04-28
Unknown · Tiny File Manager · CVE-2020-12102
**Name of the Vulnerable Software and Affected Versions** Tiny File Manager version 2.4.1 **Description** The issue allows authenticated users to enumerate directories and files on the filesystem outside of the application scope due to a Path Traversal vulnerability in the ajax recursive directory listing functionality. **Recommendations** For Tiny File Manager version 2.4.1, consider disabling the ajax recursive directory listing functionality until a patch is available to prevent exploitation of the Path Traversal vulnerability.
PT-2020-13035
7.7
2020-04-28
Unknown · Tiny File Manager · CVE-2020-12103
**Name of the Vulnerable Software and Affected Versions** Tiny File Manager version 2.4.1 **Description** The issue allows authenticated users to create backup copies of files with a .bak extension outside the intended scope in the same directory where they are stored. This is due to a vulnerability in the ajax file backup copy functionality. **Recommendations** For Tiny File Manager version 2.4.1, consider disabling the ajax file backup copy functionality until a patch is available to prevent exploitation. Restrict access to the backup copy feature to minimize the risk of unauthorized file creation.