A vulnerability has been identified in deV!Lz ClanPortal, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is due to an input validation error in the "inc/filebrowser/browser.php" script that does not validate the "file" parameter, which could be exploited by malicious users to access and disclose the contents of arbitrary files.
Vulnerable Products
Vulnerable Software: deV!Lz ClanPortal version 1.4.5 and prior