Allele Security Alert
ASA-2020-00043
Identifier(s)
ASA-2020-00043, CVE-2019-11928
Title
Cross-Site Scripting (XSS) through a specially crafted live location message
Vendor(s)
Product(s)
WhatsApp Desktop
Affected version(s)
WhatsApp Desktop versions before v0.3.4932
Fixed version(s)
WhatsApp Desktop version v0.3.4932
Proof of concept
Unknown
Description
An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed Cross-Site Scripting (XSS) upon clicking on a link from a specially crafted live location message.
Technical details
Unknown
Credits
Unknown
Reference(s)
WhatsApp Security Advisories
https://www.whatsapp.com/security/advisories/2020
CVE-2019-11928
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11928
CVE-2019-11928
https://nvd.nist.gov/vuln/detail/CVE-2019-11928
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: September 9, 2020