VYPR
Medium severity5.3NVD Advisory· Published May 18, 2020· Updated Jun 17, 2026

CVE-2019-20801

CVE-2019-20801

Description

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Readdle/Documents2 versions
    cpe:2.3:a:readdle:documents:*:*:*:*:*:iphone_os:*:*+ 1 more
    • cpe:2.3:a:readdle:documents:*:*:*:*:*:iphone_os:*:*range: <6.9.7
    • (no CPE)range: <6.9.7
  • Readdle/Documents appdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.