Vulnerability Description
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Telegram | Telegram | <= 6.0.1 |
| Telegram | Telegram Desktop | <= 2.0.1 |
References
- https://github.com/VijayT007/Vulnerability-Database/blob/master/Telegram:CVE-202Third Party Advisory
- https://github.com/VijayT007/Vulnerability-Database/blob/master/Telegram:CVE-202Third Party Advisory
FAQ
What is CVE-2020-12474?
CVE-2020-12474 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.
How severe is CVE-2020-12474?
CVE-2020-12474 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12474?
Check the references section above for vendor advisories and patch information. Affected products include: Telegram Telegram, Telegram Telegram Desktop.