Impact
An authenticated user with ability to rename files can craft a POST request to the renaming endpoint in Veno File Manager 4.4.9. By renaming the application configuration file and triggering a rebuild, the system resets the super administrator credentials to their default values, effectively allowing the attacker to assume the highest level of control. The core weakness is the lack of authorization checks and improper handling of file rename operations in the affected function, leading to a direct privilege escalation pathway.
Affected Systems
The vulnerability is present in Veno File Manager Project version 4.4.9. No specific vendor product identifiers are listed beyond the project name; users running this exact version are impacted, while later releases are assumed to have fixed the issue.
Risk and Exploitability
Currently no CVSS score or EPSS information is available for this vulnerability, and it is not listed in the CISA KEV catalog. Nonetheless, the attack requires only authenticated access with rename permissions, a capability usually granted to a limited set of trusted users. The impact is critical because it fully compromises the super administrator account. Potential attackers can construct the malicious request over HTTP to the rename endpoint, which in turn triggers the automatic configuration rebuild and credential reset. Given the straightforward nature of the exploit and the high potential impact, the risk is considered high for any environment running the affected version and lacking adequate role isolation.
OpenCVE Enrichment