An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.filez.com/securityPolicy/2.html?1744703100 |
|
History
Fri, 25 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Apr 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user. | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published: 2025-04-25T15:27:19.989Z
Updated: 2025-04-25T16:46:25.734Z
Reserved: 2025-03-06T16:09:25.537Z
Link: CVE-2025-2070
Updated: 2025-04-25T16:46:21.139Z
Status : Awaiting Analysis
Published: 2025-04-25T16:15:26.180
Modified: 2025-04-29T13:52:28.490
Link: CVE-2025-2070
No data.