CVE-2026-6497 | prasathmani TinyFileManager up to 2.6 File Upload filemanager.php?p= ajax=true&type=upload uploadurl server-side request forgery

SecurityVulns

A vulnerability has been found in prasathmani TinyFileManager up to 2.6 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the component File Upload Handler. This manipulation of the argument uploadurl causes server-side request forgery.

The identification of this vulnerability is CVE-2026-6497. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More