[GH-ISSUE #477] Security Issue with excluded folders #350

Open
opened 2026-03-02 15:58:02 +03:00 by kerem · 1 comment
Owner

Originally created by @taylorman57 on GitHub (Dec 27, 2020).
Original GitHub issue: https://github.com/prasathmani/tinyfilemanager/issues/477

The excluded folders feature is not recursive.

For example if I exclude "users" I can still put /?p=users/username and it will load the "username" folder

Originally created by @taylorman57 on GitHub (Dec 27, 2020). Original GitHub issue: https://github.com/prasathmani/tinyfilemanager/issues/477 The excluded folders feature is not recursive. For example if I exclude "users" I can still put /?p=users/username and it will load the "username" folder
Author
Owner

@prasathmani commented on GitHub (Jan 5, 2021):

as of now excluded folders will be hidden in display directory list only, but still user can access using the url, will be fixing in upcoming releases.

<!-- gh-comment-id:754322123 --> @prasathmani commented on GitHub (Jan 5, 2021): as of now excluded folders will be hidden in display directory list only, but still user can access using the url, will be fixing in upcoming releases.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tinyfilemanager#350
No description provided.