CVE Database
/

CVE-2020-8154

Back to search

CVE-2020-8154

Published: May 12, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

VendorProductVersions

n/a

Nextcloud Server

affected
18.0.3

Weaknesses (CWE)

References

openSUSE-SU-2020:0667
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0668
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0670
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:1652
vendor-advisory
x_refsource_SUSE
FEDORA-2020-c9863904de
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now