Executive brief
Veno File Manager is a web-based file management application used to organize and share files. Authenticated administrators can exploit a path traversal vulnerability in the admin dashboard to read arbitrary files on the server, potentially exposing sensitive configuration, database credentials, or other private data stored on the system.
Technical details
The vulnerability is a path traversal (directory traversal) flaw affecting the /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php endpoints in Veno File Manager 4.4.9. An authenticated attacker with super administrator privileges can craft specially formed HTTP POST and GET requests containing directory traversal sequences (e.g., ../ or absolute paths) to bypass file access restrictions. This allows reading of arbitrary files on the server filesystem. The vulnerability requires valid super administrator credentials and network access to the application. No patch information is currently available in the advisory.
Affected products
- Veno File Manager Project Veno File Manager 4.4.9
Timeline
- 2026-08-27: disclosed