tinyfilemanager icon indicating copy to clipboard operation
tinyfilemanager copied to clipboard

Excluded files and folders can still be accessed and downloaded

Open ner00 opened this issue 2 years ago • 1 comments

If a user replaces the folder or filename using the browser's element inspector, he can still access or download it. One of the most immediate and easy exploits would be the possibility of downloading the tinymanager PHP script itself containing the password hashes.

ner00 avatar Mar 19 '23 14:03 ner00

This is still a security issue.

ner00 avatar Jun 11 '23 00:06 ner00