PT-2025-53651 · Unknown · Tiny File Manager

Arrester

·

Published

2025-12-28

·

Updated

2025-12-28

·

CVE-2025-15138

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TinyFileManager versions up to 2.6
Description A path traversal flaw exists in TinyFileManager due to manipulation of the fullpath argument within the tinyfilemanager.php file. This allows for remote exploitation. The vendor was contacted regarding this issue but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15138

Affected Products

Tiny File Manager