CVE-2025-2070

An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.
Configurations

No configuration.

History

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) Se informó de una vulnerabilidad de análisis XML incorrecto en el cliente FileZ que podría permitir lecturas de archivos arbitrarias en el sistema si un usuario local visita una URL manipulada específicamente para este fin.

25 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-25 16:15

Updated : 2025-04-29 13:52


NVD link : CVE-2025-2070

Mitre link : CVE-2025-2070

CVE.ORG link : CVE-2025-2070


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference