Vulnerabilities > CVE-2019-20801 - Incorrect Authorization vulnerability in Readdle Documents
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |