Impact
The vulnerability is an access control flaw that enables an authenticated attacker to read any file uploaded by other users by crafting a specially curated GET request to the /vfm-admin/ajax/streamvid.php endpoint. This can lead to the disclosure of confidential user data.
Affected Systems
The affected product is the Veno File Manager Project, version 4.4.9. No other vendors or versions are reported, and the flaw appears to be specific to this release.
Risk and Exploitability
Because the exploit requires an authenticated session and the endpoint accepts unrestricted GET parameters, the potential attack surface is limited to users with valid credentials. No CVSS score is provided and the EPSS score is unavailable, but the fact that it enables arbitrary file reads raises the risk level. The vulnerability is not listed in CISA’s KEV catalog, so no public exploitation evidence is available yet. A likely vector is a malicious actor leveraging a legitimate user session to request the target file.
OpenCVE Enrichment