ZeroHour

CVE-2020-1904

CVSS 3.1
5.5 medium
EPSS
1%p64
Published
()
Modified
Description

A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.

Vendors
whatsapp
Products
whatsapp, whatsapp business
Weakness
CWE-23, CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.