CVE-2025-2070: Filez Client
Medium severity, CVSS 5.0. EPSS: 0.1% chance of exploitation in the next 30 days.
An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.
Affected products
- Filez Client: before 11.0.0.10 (fixed in 11.0.0.10)
Published 2025-04-25. Last modified 2026-06-17.