Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments.
History

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:opft:session:1.17.5:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Opft
Opft session
CPEs cpe:2.3:a:opft:session:1.17.5:*:*:*:*:android:*:*
Vendors & Products Opft
Opft session

Mon, 19 May 2025 17:00:00 +0000

Type Values Removed Values Added
Description Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments. Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments.
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2024-02-29T23:37:37.339Z

Updated: 2025-05-19T16:56:56.891Z

Reserved: 2024-02-29T23:31:27.739Z

Link: CVE-2024-2045

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:37.761Z

cve-icon NVD

Status : Modified

Published: 2024-03-01T00:15:52.493

Modified: 2025-05-19T17:15:22.250

Link: CVE-2024-2045

cve-icon Redhat

No data.