In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.
History

Wed, 31 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Prasathmani
Prasathmani tiny File Manager
CPEs cpe:2.3:a:tiny_file_manager_project:tiny_file_manager:2.4.1:*:*:*:*:*:*:* cpe:2.3:a:prasathmani:tiny_file_manager:2.4.1:*:*:*:*:*:*:*
Vendors & Products Tiny File Manager Project
Tiny File Manager Project tiny File Manager
Prasathmani
Prasathmani tiny File Manager

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-04-28T21:07:28

Updated: 2024-08-04T11:48:58.008Z

Reserved: 2020-04-23T00:00:00

Link: CVE-2020-12103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-28T22:15:12.780

Modified: 2025-12-31T19:40:50.980

Link: CVE-2020-12103

cve-icon Redhat

No data.