LiveActive security incident?Get immediate response
CVE Record

CVE-2019-20801: An issue was discovered in the Readdle Documents app before 6.9.7 for iOS.

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Older Readdle Documents for iOS versions exposed user files through its local file-transfer features. The issue allowed any website the user visited to make cross-origin requests and access data through weak server authorization. The affected range is before version 6.9.7.

Executive priority

Prioritize remediation where staff store sensitive files in Readdle Documents. The issue is not KEV-listed, but the data-access impact justifies targeted mobile app inventory and update enforcement.

Technical view

CVE-2019-20801 concerns Readdle Documents for iOS before 6.9.7. Its file-transfer web server allowed requests from any origin, and its WebSocket server lacked authorization control. The stated impact is JavaScript from any website accessing user data via cross-origin requests.

Likely exposure

Exposure is limited to iOS devices running Readdle Documents before 6.9.7, especially where the app's file-transfer web server is enabled or reachable while the user browses the web.

Exploitation context

The provided sources do not report active exploitation, and the CVE is not listed as KEV. The attack condition described is a user visiting any website while the vulnerable app service can be accessed.

Researcher notes

Evidence is sparse: no CVSS, CWE, or detailed affected CPE data is provided. The strongest technical signals are permissive cross-origin behavior on the file-transfer web server and missing WebSocket authorization before 6.9.7.

Mitigation direction

  • Upgrade Readdle Documents for iOS to version 6.9.7 or later.
  • Check Readdle and Apple App Store guidance for current supported versions.
  • Disable or avoid file-transfer server use until devices are updated.
  • Use MDM controls to identify and update stale iOS app installs.

Validation and detection

  • Inventory iOS devices for Readdle Documents installations and versions.
  • Confirm no managed device remains below version 6.9.7.
  • Review mobile risk telemetry for unexpected local file-transfer service exposure.
  • Document whether business workflows rely on Documents file-transfer features.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-20801 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.