Session version 1.17.5 allows obtaining internal application files and public
files from the user's device without the user's consent. This is possible
because the application is vulnerable to Local File Read via chat attachments.
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:opft:session:1.17.5:*:*:*:*:*:*:* | |
Metrics |
ssvc
|
Mon, 19 May 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Opft
Opft session |
|
CPEs | cpe:2.3:a:opft:session:1.17.5:*:*:*:*:android:*:* | |
Vendors & Products |
Opft
Opft session |
Mon, 19 May 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments. | Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments. |
Metrics |
cvssV3_1
|
cvssV3_1
|

Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2024-02-29T23:37:37.339Z
Updated: 2025-05-19T16:56:56.891Z
Reserved: 2024-02-29T23:31:27.739Z
Link: CVE-2024-2045

Updated: 2024-08-01T19:03:37.761Z

Status : Modified
Published: 2024-03-01T00:15:52.493
Modified: 2025-05-19T17:15:22.250
Link: CVE-2024-2045

No data.