CVE-2020-1908Improper Authorization in Whatsapp Business FOR IOS

Severity
4.6MEDIUMNVD
EPSS
0.1%
top 69.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 3
Latest updateMay 24

Description

Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5facebook/whatsapp_business_for_iosunspecified2.20.100+1
NVDwhatsapp/whatsapp< 2.20.100
CVEListV5facebook/whatsapp_for_iosunspecified2.20.100+1

🔴Vulnerability Details

2
GHSA
GHSA-gqf3-x727-h474: Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v22022-05-24
CVEList
CVE-2020-1908: Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v22020-11-03

💥Exploits & PoCs

1
Exploit-DB
rConfig 3.9.4 - 'search.crud.php' Remote Command Injection2020-03-23
CVE-2020-1908 — Improper Authorization | cvebase