{"api_version":"1","generated_at":"2026-07-23T13:38:23+00:00","cve":"CVE-2020-20093","urls":{"html":"https://cve.report/CVE-2020-20093","api":"https://cve.report/api/cve/CVE-2020-20093.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-20093","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-20093"},"summary":{"title":"CVE-2020-20093","description":"The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-03-23 22:15:00","updated_at":"2022-03-30 16:55:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://github.com/zadewg/RIUS","name":"https://github.com/zadewg/RIUS","refsource":"MISC","tags":[],"title":"GitHub - zadewg/RIUS: RTLO Injection URI Spoofing","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/166448/RTLO-Injection-URI-Spoofing.html","name":"http://packetstormsecurity.com/files/166448/RTLO-Injection-URI-Spoofing.html","refsource":"MISC","tags":[],"title":"RTLO Injection URI Spoofing ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-20093","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-20093","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"20093","vulnerable":"1","versionEndIncluding":"227.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"facebook","cpe5":"messenger","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"20093","vulnerable":"1","versionEndIncluding":"228.1.0.10.116","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"facebook","cpe5":"messenger","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-20093","qid":"630809","title":"Facebook Messenger app For Android and iOS URI Spoofing Vulnerability"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-20093","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/zadewg/RIUS","refsource":"MISC","name":"https://github.com/zadewg/RIUS"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/166448/RTLO-Injection-URI-Spoofing.html","url":"http://packetstormsecurity.com/files/166448/RTLO-Injection-URI-Spoofing.html"}]}},"nvd":{"publishedDate":"2022-03-23 22:15:00","lastModifiedDate":"2022-03-30 16:55:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:facebook:messenger:*:*:*:*:*:iphone_os:*:*","versionEndIncluding":"227.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:facebook:messenger:*:*:*:*:*:android:*:*","versionEndIncluding":"228.1.0.10.116","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"20093","Ordinal":"181502","Title":"CVE-2020-20093","CVE":"CVE-2020-20093","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"20093","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}