In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is not propagated to the extracted files.
References
Configurations
No configuration.
History
26 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-26 18:15
Updated : 2025-04-26 18:15
NVD link : CVE-2025-46652
Mitre link : CVE-2025-46652
CVE.ORG link : CVE-2025-46652
JSON object : View
Products Affected
No product.
CWE
CWE-830
Inclusion of Web Functionality from an Untrusted Source