Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| http://veno.com |
|
| https://github.com/jfs-jfs/CVE-2026-37066 |
|
History
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal Enables Arbitrary File Read by Authenticated Super Administrator in Veno File Manager |
Wed, 02 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 28 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal Enables Arbitrary File Read by Authenticated Super Administrator in Veno File Manager | |
| Weaknesses | CWE-22 |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-27T00:00:00.000Z
Updated: 2026-09-02T18:28:36.410Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37066
No data.
Status : Deferred
Published: 2026-08-27T20:17:42.393
Modified: 2026-09-02T19:17:17.160
Link: CVE-2026-37066
No data.