Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2020-1904

MEDIUM 5.5

A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.

Attack vector : Local No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS 1.11% above median percentile 63.0%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (2)
Vendor Product Versions
whatsapp whatsapp
iOS
<2.20.61
whatsapp whatsapp_business
iOS
<2.20.61
View on NVD ↗ Advisory · www.whatsapp.com