Impact
An incorrect access control flaw in the /vfm-admin/ajax/sendfiles.php endpoint of Veno File Manager Project allows an unauthenticated user to send emails through the application's SMTP server. By crafting a POST request with the necessary parameters and headers, an attacker can trigger the application to deliver arbitrary messages. This can be leveraged for phishing, spam, or other types of email-based social engineering attacks.
Affected Systems
The vulnerability affects Veno File Manager Project version 4.4.9. No other vendors or product versions are listed as affected.
Risk and Exploitability
The endpoint is publicly reachable and requires no authentication, implying an attacker can exploit it without prior compromise. While no EPSS data or CVSS score is present, the potential to cause widespread email abuse makes the risk high. The attack vector is inferred to be internet-based access to the application, and the absence of official mitigation guidance indicates that default defenses are insufficient.
OpenCVE Enrichment