A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.
References
Link | Resource |
---|---|
https://www.whatsapp.com/security/advisories/2020/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-10-06 11:15
Updated : 2022-02-04 16:06
NVD link : CVE-2020-1904
Mitre link : CVE-2020-1904
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
- whatsapp_business