Improper Validation of Specified Type of Input
CVE-2024-8058
Summary
An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.
- LOW
- NETWORK
- LOW
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- LOW
CWE-1287 - Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
References
Advisory Timeline
- Published