Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services.
References
| Link | Resource |
|---|---|
| https://github.com/RobertoLuzanilla/tinyfilemanager-security-advisories/blob/main/CVE-2025-46651.md | Third Party Advisory Mitigation |
| https://github.com/prasathmani/tinyfilemanager/blob/master/tinyfilemanager.php#L608 | Product |
Configurations
History
10 Feb 2026, 20:53
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Prasathmani tiny File Manager
Prasathmani |
|
| References | () https://github.com/RobertoLuzanilla/tinyfilemanager-security-advisories/blob/main/CVE-2025-46651.md - Third Party Advisory, Mitigation | |
| References | () https://github.com/prasathmani/tinyfilemanager/blob/master/tinyfilemanager.php#L608 - Product | |
| CPE | cpe:2.3:a:prasathmani:tiny_file_manager:*:*:*:*:*:*:*:* |
05 Feb 2026, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
04 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-918 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
03 Feb 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-03 18:16
Updated : 2026-02-10 20:53
NVD link : CVE-2025-46651
Mitre link : CVE-2025-46651
CVE.ORG link : CVE-2025-46651
JSON object : View
Products Affected
prasathmani
- tiny_file_manager
CWE
CWE-918
Server-Side Request Forgery (SSRF)
