Impact
The vulnerability disclosed in Veno File Manager Project 4.4.9 is an absolute path disclosure located in the script RelativePath.Example1.php within /vfm-admin/assets/zipstream/grandt/relativepath/. By sending a simple GET request to the exposed endpoint, an unauthenticated attacker learns the full system directory in which the application code resides. This leak reveals internal directory structure but does not expose file contents or allow code execution; it only provides location information that could assist in future attacks.
Affected Systems
Veno File Manager Project version 4.4.9 is affected. No other vendors or products are listed. The flaw specifically impacts the RelativePath.Example1.php script under /vfm-admin/assets/zipstream/grandt/relativepath/.
Risk and Exploitability
The flaw can be exploited over the network by any host that can issue HTTP requests to the web server hosting Veno File Manager. No authentication is required, so the attack vector is unauthenticated. The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known large‑scale deployments of exploits yet. Nevertheless, revealing directory structure can aid adversaries in mapping the filesystem and targeting subsequent weaknesses, thereby warranting moderate risk assessment.
OpenCVE Enrichment