First published: Tue Oct 06 2020(Updated: )
A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Whatsapp Whatsapp | <2.20.61 | |
Whatsapp Whatsapp Business | <2.20.61 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1904.
The severity level of CVE-2020-1904 is medium.
WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 are affected.
CVE-2020-1904 has a path validation issue.
An attacker could overwrite files by sending specially crafted docx, xlsx, and pptx files as attachments to messages.