Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://veno.com |
|
| https://github.com/jfs-jfs/CVE-2026-37066 |
|
History
Fri, 28 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal Enables Arbitrary File Read by Authenticated Super Administrator in Veno File Manager | |
| Weaknesses | CWE-22 |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-27T18:53:51.422Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37066
No data.
Status : Received
Published: 2026-08-27T20:17:42.393
Modified: 2026-08-27T20:17:42.393
Link: CVE-2026-37066
No data.
OpenCVE Enrichment
Updated: 2026-08-28T06:00:14Z
Weaknesses