PT-2019-14981 · Tencent · Tencent Wechat

Junzhi Lu

+2

·

Published

2019-12-31

·

Updated

2020-01-14

·

CVE-2019-17151

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tencent WeChat versions prior to 7.0.9
Description This issue allows remote attackers to redirect users to an external resource on affected installations. User interaction is required, as the target must be within a chat session with the attacker. The flaw exists within the parsing of a user's profile, specifically in the failure to properly validate a user's name, stored in the name variable. An attacker can leverage this, potentially in conjunction with other issues, to execute code in the context of the current process.
Recommendations For versions prior to 7.0.9, update to version 7.0.9 or later to resolve the issue. As a temporary workaround, consider restricting user interactions within chat sessions to minimize the risk of exploitation.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17151
ZDI-19-1035

Affected Products

Tencent Wechat