Medium severity4.3NVD Advisory· Published Feb 3, 2026· Updated Jun 17, 2026
CVE-2025-46651
CVE-2025-46651
Description
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:prasathmani:tiny_file_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:prasathmani:tiny_file_manager:*:*:*:*:*:*:*:*range: <=2.6
- (no CPE)range: <=2.6
- Tiny File Manager/Tiny File Managerdescription
- Range: <=2.6
- Range: <=2.6
Patches
Vulnerability mechanics
References
2- github.com/RobertoLuzanilla/tinyfilemanager-security-advisories/blob/main/CVE-2025-46651.mdnvdMitigationThird Party Advisory
- github.com/prasathmani/tinyfilemanager/blob/master/tinyfilemanager.phpnvdProduct
News mentions
0No linked articles in our index yet.