← Voltar à pesquisa de CVEs

CVE-2026-37066

Veno File Manager Project

Descrição

Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.

EPSS 0.189%Risco 0
Ver fonte
Publicação
2026-08-27 20:17:42
Versões afetadas
<4.4.9
Tipo
Aplicação web
Última alteração
2026-08-27 20:17:42
Vetor
Pending