Vulnerability · NVD
CVE-2020-1904
MEDIUM 5.5
A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.
Attack vector : Local
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
1.11%
above median
percentile 63.0%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
whatsapp iOS
|
iOS | <2.20.61 | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* | |
|
whatsapp_business iOS
|
iOS | <2.20.61 | cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:* |