CVE-2019-11928: XSS
Published Sep 3, 2020
·Updated
An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.
Affected Software
1 affected component
WhatsApp WhatsApp Desktop<0.3.4932
Event History
Sep 3, 2020
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-11928.
2
What is the severity of CVE-2019-11928?
The severity of CVE-2019-11928 is medium.
3
What is the affected software?
The affected software is WhatsApp Desktop versions prior to v0.3.4932.
4
What is the potential impact of this vulnerability?
This vulnerability could allow cross-site scripting upon clicking on a link from a specially crafted live location message.
5
Is there a fix available for CVE-2019-11928?
Yes, upgrading to WhatsApp Desktop version v0.3.4932 or newer will fix this vulnerability.