Executive brief
Veno File Manager Project is a web-based file management application used to organize and share files across systems. An unauthenticated attacker can enumerate valid usernames by sending specially crafted requests to an admin endpoint, potentially enabling targeted account takeover attempts or social engineering attacks. This information disclosure allows attackers to build a list of valid users before launching credential-based attacks.
Technical details
A user enumeration vulnerability exists in the /vfm-admin/ajax/usr-check.php endpoint in Veno File Manager Project 4.4.9. The vulnerability is triggered by sending a POST request with a crafted 'user_name' parameter to test whether a user account exists. The endpoint fails to enforce authentication checks and does not rate-limit or obfuscate responses, allowing an unauthenticated attacker to systematically enumerate valid usernames. No authentication is required to exploit this vulnerability; the attack is network-accessible. An attacker can retrieve a complete list of application users to facilitate follow-up attacks such as brute-force password guessing or targeted social engineering. Patches or vendor updates addressing this issue have not been confirmed at this time.
Affected products
- <UNKNOWN> Veno File Manager Project 4.4.9
Timeline
- 2026-08-27: disclosed
- 2026-08-27: advisory: CVE-2026-37064 published