Server-Side Request Forgery in TinyFileManager by prasathmani
CVE-2026-6497
Key Information:
- Vendor
Prasathmani
- Status
- Vendor
- CVE Published:
- 17 April 2026
Badges
What is CVE-2026-6497?
A vulnerability exists in TinyFileManager, specifically in the file upload functionality located at /filemanager.php?p=ajax=true&type=upload. This flaw allows an attacker to manipulate the uploadurl parameter, potentially leading to a server-side request forgery (SSRF) attack. Such an attack can be initiated remotely, enabling the attacker to send unauthorized requests to internal services. Despite early disclosure efforts to the vendor, there has been no response or action taken, leaving users at risk of exploitation.
Affected Version(s)
TinyFileManager 2.0
TinyFileManager 2.1
TinyFileManager 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
