Beveiligingsadvies

CVE-2026-37070

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-27 00:00:00
Laatst bijgewerkt 2026-09-02 18:18:03
Toegewezen door mitre
CVSS-score 6.5
Status PUBLISHED

Beschrijving

Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.