ZeroHour

CVE-2019-15619

CVSS 3.1
4.8 medium
EPSS
<1%p56
Published
()
Modified
Description

Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.

Vendors
nextcloud
Products
deck, nextcloud server, talk
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.