PT-2020-15158 · Facebook · Whatsapp For Ios+1

Published

2020-10-06

·

Updated

2022-02-05

·

CVE-2020-1904

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WhatsApp for iOS versions prior to 2.20.61 WhatsApp Business for iOS versions prior to 2.20.61
Description A path validation issue could have allowed for directory traversal, overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.
Recommendations For WhatsApp for iOS versions prior to 2.20.61, update to version 2.20.61 or later. For WhatsApp Business for iOS versions prior to 2.20.61, update to version 2.20.61 or later.

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1904

Affected Products

Whatsapp Business For Ios
Whatsapp For Ios