Executive brief
Veno File Manager Project is a web-based file management application. An unauthenticated attacker can bypass access controls to extract application logs from the server via a specially crafted request, potentially exposing sensitive operational data, user activities, and system information contained in those logs.
Technical details
The vulnerability is an access control bypass in the /vfm-admin/admin-panel/view/save-cvs.php endpoint in Veno File Manager Project 4.4.9. The vulnerable component fails to properly authenticate or authorize requests before processing them, allowing an unauthenticated attacker to submit a specially crafted POST request to extract application logs from a specified date forward. This is a classic broken authentication / authorization flaw that exposes sensitive diagnostic and operational logs without requiring prior authentication. An attacker can retrieve logs remotely via the network without credentials or user interaction.
Affected products
- Veno File Manager Project Veno File Manager Project 4.4.9
Timeline
- 2026-08-27: disclosed