Rewterz
Rewterz Threat Advisory – CVE-2020-6969 – ICS: AutomationDirect C-More Touch Panels
February 6, 2020
Rewterz
Rewterz Threat Advisory – ICS: Medtronic Conexus Radio Frequency Telemetry Protocol
February 7, 2020

Rewterz Threat Advisory – CVE-2019-18426 – WhatsApp Bug Allows Malicious Code-Injection

Severity

High

Analysis summary

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

rich preview link

Impact

Cross-site scripting

Affected Vendors

WhatsApp

Affected Products

WhatsApp Desktop prior to v0.3.9309 paired with WhatsApp for iPhone versions prior to 2.20.10

Remediation

Update to the latest version.