Impact
The vulnerability arises from a crafted POST request to /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 that reveals whether a supplied user_name exists. This flaw allows an unauthenticated attacker to enumerate application users through a specialized request, disclosing internal account information that could be leveraged for credential guessing or social engineering. The weakness is linked to improper access controls that permit disclosure of user existence data.
Affected Systems
The issue strictly affects Veno File Manager Project version 4.4.9; no other vendors, products, or versions are publicly identified.
Risk and Exploitability
Based on the description, the likely attack vector is remote over the network, requiring only the ability to send a POST request to the vulnerable endpoint. The CVSS score of 5.3 signals a moderate severity, while the EPSS score of <1% indicates a low probability of real‑world exploitation. The vulnerability is not present in CISA KEV. Although enumeration can be a stepping‑stone to further attacks, the current risk level remains moderate.
OpenCVE Enrichment