CyberRota Analysis
AI-GeneratedThe Veno File Manager Project version 4.4.9 is vulnerable to a path traversal flaw that enables authenticated attackers with super administrator privileges to read arbitrary files on the server. This vulnerability can lead to the exposure of sensitive information through specially crafted HTTP requests to specific endpoints. Organizations using this version of the software should prioritize remediation to mitigate potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.