Impact
Veno File Manager Project 4.4.9 suffers from an incorrect access control flaw in the admin-head-updates.php file. This weakness allows an attacker who can gain any level of user authentication to execute functions reserved for administrators, potentially enabling unauthorized file modifications, configuration changes, or further exploitation of the web application. The flaw directly compromises the integrity and confidentiality of data managed by the file manager, and may also impact availability if an attacker deletes or corrupts critical files.
Affected Systems
The affected product is Veno File Manager Project version 4.4.9. No other versions or vendors are listed as impacted.
Risk and Exploitability
The vulnerability is reported as an access-control issue with no explicit severity score or exploitation probability available. It is likely exploitable via the web interface by authenticated users, meaning that once an attacker obtains basic user credentials the elevated privileges can be triggered. Because the flaw is not listed in the CISA KEV catalog and no EPSS score is provided, the current risk assessment remains uncertain but could be moderate to high for systems that expose the Veno File Manager to untrusted networks.
OpenCVE Enrichment