Impact
Veno File Manager Project version 4.4.9 contains an incorrect access control flaw in the admin-head-updates.php file. The vulnerability is a CWE‑284 weakness that allows any authenticated user to invoke functions that are reserved for administrators, potentially enabling unauthorized file modifications, configuration changes, and further exploitation of the web application. The compromise jeopardizes the integrity, confidentiality, and possibly the availability of the data managed by the file manager.
Affected Systems
The affected product is Veno File Manager Project, version 4.4.9. No other versions or vendors are listed as impacted.
Risk and Exploitability
Based on the description, it is inferred that the exploitation vector is the web interface, requiring only that an attacker gain basic user authentication. The CVSS score of 9.8 reflects severe impact, while the EPSS score of < 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, so the risk is uncertain but potentially high for systems that expose Veno File Manager to untrusted networks.
OpenCVE Enrichment