Home
HIGH: 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:LDefault status
unaffected
Any version before 9.8.6.0
affected
Description
An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.
Problem types
CWE-1287 Improper Validation of Specified Type of Input
Product status
Any version before 9.8.6.0
Credits
Lenovo thanks HisJane for reporting this issue.
References
www.filez.com/securityPolicy/1.html?1733849740