
A Path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager Project's Tiny File Manager <= 2.4.6 allows remote attackers with valid user accounts to upload malicious PHP files to the webroot and achieve code execution on the target server.
Eine Path-Traversal-Schwachstelle in der Datei-Upload-Funktionalität in tinyfilemanager.php in Tiny File Manager <= 2.4.6 des Tiny File Manager-Projekts ermöglicht Remote-Angreifern mit gültigen Benutzerkonten, bösartige PHP-Dateien in das Webroot hochzuladen und auf dem Zielserver Codeausführung zu erreichen.