Back

MEDIUM

Session 1.17.5 - LFR via chat attachment

Published Feb 29, 2024

Description

Session version 1.17.5 allows obtaining internal application files and public

files from the user's device without the user's consent. This is possible

because the application is vulnerable to Local File Read via chat attachments.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Feb 29, 2024
Updated May 19, 2025
Reserved Feb 29, 2024
CISA Vulnrichment
Updated Mar 6, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Fluid Attacks
Published Feb 29, 2024
Updated May 19, 2025
Exploited since n/a
EUVD-2024-27011