Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-37072 — Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php | Kitploit
Tools/GitHubGitHub/jfs-jfs/cve-2026-37072
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingMisconfiguration
GitHubjfs-jfs/cve-2026-37072

CVE-2026-37072

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php

View Repository
2 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-37072

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php

An unauthenticated attacker can exploit a Local File Inclusion vulnerability in the 'lang' GET parameter. By sending a specially crafted POST request with the right file inclusion in the 'lang' url parameter the attacker can corrupt the configuration file. Then by sending a GET request to the setup endpoint can force a partial regeneration of the configuration file as well as resetting the superadministrator password to the default value, resulting in full administrative access. No user interaction is required.

https://github.com/user-attachments/assets/8fb29ee8-57a6-42ba-bf49-68f6a883b0f6

Download Tool