CVE-2025-15138 | prasathmani TinyFileManager up to 2.6 tinyfilemanager.php fullpath path traversal (EUVD-2025-205510)
A vulnerability identified as critical has been detected in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argument fullpath causes path traversal.
This vulnerability is registered as CVE-2025-15138. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.