CVE-2020-1904: Path Traversal
Published Oct 6, 2020
·Updated
A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.
Affected Software
2 affected components
WhatsApp Whatsapp Iphone Os<2.20.61
WhatsApp Whatsapp Business Iphone Os<2.20.61
Event History
Oct 6, 2020
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
CVE-2020-1904.
2
What is the severity level of CVE-2020-1904?
The severity level of CVE-2020-1904 is medium.
3
Which software versions are affected by CVE-2020-1904?
WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 are affected.
4
What kind of issue does CVE-2020-1904 have?
CVE-2020-1904 has a path validation issue.
5
What can an attacker do with CVE-2020-1904?
An attacker could overwrite files by sending specially crafted docx, xlsx, and pptx files as attachments to messages.