PT-2020-13035 · Unknown · Tiny File Manager

Peefour

·

Published

2020-04-28

·

Updated

2025-12-31

·

CVE-2020-12103

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tiny File Manager version 2.4.1
Description The issue allows authenticated users to create backup copies of files with a .bak extension outside the intended scope in the same directory where they are stored. This is due to a vulnerability in the ajax file backup copy functionality.
Recommendations For Tiny File Manager version 2.4.1, consider disabling the ajax file backup copy functionality until a patch is available to prevent exploitation. Restrict access to the backup copy feature to minimize the risk of unauthorized file creation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-12103

Affected Products

Tiny File Manager