CVE-2024-2045
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
01/03/2024
Last modified:
19/05/2025
Description
Session version 1.17.5 allows obtaining internal application files and public<br />
<br />
files from the user&#39;s device without the user&#39;s consent. This is possible<br />
<br />
because the application is vulnerable to Local File Read via chat attachments.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:opft:session:1.17.5:*:*:*:*:android:*:* |
To consult the complete list of CPE names with products and versions, see this page



