Impact
The vulnerability is an absolute path disclosure located in the file RelativePath.Example1.php within the Veno File Manager Project 4.4.9. An unauthenticated attacker can trigger the flaw by sending a GET request to the exposed endpoint, causing the application to reveal the absolute system path where the code is running. This disclosure of internal directory structure does not permit execution of code or privilege escalation, but it aids threat actors in mapping the file system and locating potential future vulnerabilities. The weakness is a classic example of an information‑disclosure flaw.
Affected Systems
Veno File Manager Project 4.4.9 is affected. No other vendors or product versions are listed. The specific component impacted is the RelativePath.Example1.php script located under /vfm-admin/assets/zipstream/grandt/relativepath/.
Risk and Exploitability
The flaw is exploitable over the network by any host able to issue HTTP requests to the web server hosting the Veno File Manager. Because authentication is not required, it is an unauthenticated attack vector. The CVSS score is not provided, and the EPSS score is unavailable, so exact exploitation probability cannot be quantified from the data. The vulnerability is not included in the CISA KEV catalog, indicating no known large‑scale exploitation. Nonetheless, the ability to map the configuration of a target system can significantly aid further attacks and should be treated as a moderate to high risk in many environments.
OpenCVE Enrichment