Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2024-02-29T23:37:37.339Z

Updated: 2024-08-01T19:03:37.761Z

Reserved: 2024-02-29T23:31:27.739Z

Link: CVE-2024-2045

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:37.761Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-01T00:15:52.493

Modified: 2024-03-01T14:04:26.010

Link: CVE-2024-2045

cve-icon Redhat

No data.