Path Validation Issue in WhatsApp for iOS and WhatsApp Business for iOS
CVE-2020-1904

5.5MEDIUM

Key Information:

Vendor

Facebook

Vendor
CVE Published:
6 October 2020

What is CVE-2020-1904?

A vulnerability in WhatsApp for iOS and WhatsApp Business for iOS prior to version 2.20.61 could potentially allow an attacker to exploit a path validation flaw. This situation arises when specially crafted attachments, such as docx, xlsx, and pptx files, are sent through messages, leading to the possibility of directory traversal that could overwrite files on the device. Users should be aware of this issue and update their applications to the latest versions to mitigate any risks.

Affected Version(s)

WhatsApp Business for iOS 2.20.61

WhatsApp Business for iOS < 2.20.61

WhatsApp for iOS 2.20.61

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-1904 : Path Validation Issue in WhatsApp for iOS and WhatsApp Business for iOS