Executive brief
Veno File Manager is a web-based file management application used to store and organize files. An unauthenticated attacker can exploit a file inclusion flaw to corrupt the application's configuration, then reset the superadministrator password to its default value, gaining full administrative control without requiring valid credentials or user interaction.
Technical details
The vulnerability is an Incorrect Access Control flaw in the admin-head-updates.php file that allows unauthenticated attackers to exploit a Local File Inclusion (LFI) vulnerability via the 'lang' GET parameter. An attacker sends a specially crafted POST request with a malicious file inclusion payload to corrupt the application's configuration file. Subsequently, a GET request to the setup endpoint forces a partial regeneration of the configuration and resets the superadministrator password to a default value. The attack requires no authentication, user interaction, or network-level preconditions beyond HTTP access to the application. The exploit results in complete administrative compromise, allowing the attacker to perform any privileged operation within the application.
Affected products
- Veno Veno File Manager Project 4.4.9
Timeline
- 2026-08-27: disclosed