CVE-2026-37073: Veno Veno File Manager Project vulnerability
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Instances of Veno File Manager Project 4.4.9 with the affected /vfm-admin/ajax/sendfiles.php endpoint reachable by an attacker are exposed. The issue can be abused without authenticating to the application.
What does an attacker need to exploit it?
An attacker needs to send a POST request to the affected endpoint with the required parameters and header. Successful exploitation uses the SMTP server configured for the application to send email.
What is the practical impact of exploitation?
An attacker can send emails through the application's configured SMTP server. This could allow unauthorized use of that server for email delivery.