Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22550
Reference (s):
- https://codecanyon.net/item/veno-file-manager-host-and-share-files/6114247
- https://gist.github.com/Sp3eD-X/22640377f96340544baf12891f708b8f

