Soliton Systems FileZen
cpe:2.3:a:soliton:filezen:*:*:*:*:*:*:*
- >= 5.0.0, <= 5.0.10
- >= 4.2.1, <= 4.2.8
This vulnerability is being actively exploited in the wild.
A command injection vulnerability has been identified in FileZen versions 4.2.1 through 4.2.8 and 5.0.0 through 5.0.10. When the FileZen Antivirus Check Option is enabled, a logged-in user can send a specially crafted HTTP request that executes arbitrary operating system commands. This vulnerability requires the attacker to have access to a user account on the system.
Exploitation of this vulnerability allows authenticated users to execute arbitrary operating system commands on the server where FileZen is running.
Users are advised to update FileZen to version 5.0.11 or later. For versions 4.2.1 to 5.0.10, there is no workaround available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.