Executive brief
FileThingie, a web-based file management tool, contains a security flaw that allows users to move files outside of their permitted folders. By manipulating the web address during a file move operation, an attacker with basic login access can bypass security restrictions to write or move files into sensitive system directories. This could lead to a complete takeover of the web server or the deletion of critical system files.
Technical details
A path traversal vulnerability exists in FileThingie v.2.5.7 due to flawed logic in the 'move' action within ft2.php. The application attempts to prevent directory traversal by comparing the number of '../' sequences in the destination path against the number of '/' characters in the current directory path. An attacker can bypass this check using 'slash inflation'—submitting a directory parameter containing a large number of redundant forward slashes (e.g., '////'). Because the underlying OS and PHP libraries normalize multiple slashes into a single separator, the attacker can satisfy the count-based validation while traversing to arbitrary locations on the file system. This allows an authenticated attacker to move or write files to sensitive directories outside the application root.
Affected products
- Andreas Haugstrup Pedersen (leefish) FileThingie 2.5.7
Timeline
- 2026-07-20: disclosed: CVE-2026-51027 published