Session version 1.17.5 allows obtaining internal application files and public
files from the user's device without the user's consent. This is possible
because the application is vulnerable to Local File Read via chat attachments.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2024-02-29T23:37:37.339Z
Updated: 2024-08-01T19:03:37.761Z
Reserved: 2024-02-29T23:31:27.739Z
Link: CVE-2024-2045

Updated: 2024-08-01T19:03:37.761Z

Status : Awaiting Analysis
Published: 2024-03-01T00:15:52.493
Modified: 2024-11-21T09:08:55.243
Link: CVE-2024-2045

No data.