prasathmani / tinyfilemanager

Single-file PHP file manager, browser and manage your files efficiently and easily with tinyfilemanager
https://tinyfilemanager.github.io
GNU General Public License v3.0
4.99k stars 1.67k forks source link

Excluded files and folders can still be accessed and downloaded #991

Open ner00 opened 1 year ago

ner00 commented 1 year ago

If a user replaces the folder or filename using the browser's element inspector, he can still access or download it. One of the most immediate and easy exploits would be the possibility of downloading the tinymanager PHP script itself containing the password hashes.

ner00 commented 1 year ago

This is still a security issue.