Back to search
CVE-2019-15619
Published: Feb 4, 2020
Modified: Aug 5, 2024
PUBLISHED
Description
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
| Vendor | Product | Versions |
|---|---|---|
n/a | Nextcloud Server | affected 16.0.4 |
Weaknesses (CWE)
References
https://hackerone.com/reports/662204
x_refsource_MISC
https://nextcloud.com/security/advisory/?id=NC-SA-2020-008
x_refsource_MISC
https://nextcloud.com/security/advisory/?id=NC-SA-2020-009
x_refsource_MISC
https://nextcloud.com/security/advisory/?id=NC-SA-2020-010
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now