[GH-ISSUE #991] Excluded files and folders can still be accessed and downloaded #638

Open
opened 2026-03-02 16:00:27 +03:00 by kerem · 1 comment
Owner

Originally created by @ner00 on GitHub (Mar 19, 2023).
Original GitHub issue: https://github.com/prasathmani/tinyfilemanager/issues/991

If a user replaces the folder or filename using the browser's element inspector, he can still access or download it. One of the most immediate and easy exploits would be the possibility of downloading the tinymanager PHP script itself containing the password hashes.

Originally created by @ner00 on GitHub (Mar 19, 2023). Original GitHub issue: https://github.com/prasathmani/tinyfilemanager/issues/991 If a user replaces the folder or filename using the browser's element inspector, he can still access or download it. One of the most immediate and easy exploits would be the possibility of downloading the tinymanager PHP script itself containing the password hashes.
Author
Owner

@ner00 commented on GitHub (Jun 11, 2023):

This is still a security issue.

<!-- gh-comment-id:1585897279 --> @ner00 commented on GitHub (Jun 11, 2023): This is still a security issue.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tinyfilemanager#638
No description provided.