Vulnerability Details CVE-2024-2045
Session version 1.17.5 allows obtaining internal application files and public
files from the user's device without the user's consent. This is possible
because the application is vulnerable to Local File Read via chat attachments.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.6%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2024-2045
-
cpe:2.3:a:opft:session:1.17.5