Impact
A crafted POST request to the /vfm-admin/ajax/usr-check.php endpoint can reveal whether a chosen user_name exists in the Veno File Manager Project 4.4.9 system. The vulnerability allows an attacker to enumerate all user accounts without authentication and potentially gain sensitive information about the user structure. This exposure can facilitate further targeted attacks such as credential guessing or social engineering, compromising the confidentiality of the system.
Affected Systems
The vulnerability is specific to Veno File Manager Project version 4.4.9. No other vendor or product information was publicly disclosed in the advisory.
Risk and Exploitability
The attack vector appears to be remote over the network, with the attacker needing only to send a POST request to the vulnerable endpoint. Because the vulnerability does not require prior authentication, the risk profile is elevated. EPSS data is not available, and the issue is not listed in CISA's KEV catalog. While the CVSS score is not provided, the ability to enumerate users could serve as a stepping stone to higher‑impact exploits, warranting moderate to high vigilance.
OpenCVE Enrichment