PT-2024-18665 · Session · Session
Carlos Bello
·
Published
2024-02-29
·
Updated
2025-05-19
·
CVE-2024-2045
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Session version 1.17.5
Description
The application is vulnerable to Local File Read via chat attachments, allowing internal application files and public files from the user's device to be obtained without the user's consent.
Recommendations
For Session version 1.17.5, consider disabling the chat attachment feature until a patch is available to prevent exploitation of the Local File Read vulnerability. Restrict access to sensitive files and directories to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Session