{ "schema_version": "1.4.0", "id": "GHSA-xg5f-prh7-r529", "modified": "2022-05-24T17:18:01Z", "published": "2022-05-24T17:18:01Z", "aliases": [ "CVE-2019-20801" ], "details": "An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20801" }, { "type": "WEB", "url": "https://apps.apple.com/us/app/documents-by-readdle/id364901807" }, { "type": "WEB", "url": "https://logicaltrust.net/blog/2019/12/documents.html#authorization" } ], "database_specific": { "cwe_ids": [ "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-05-18T00:15:00Z" } }