ZeroHour

CVE-2020-8189

PoC
CVSS 3.1
5.4 medium
EPSS
1%p71
Published
()
Modified
Description

A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.

Vendors
nextcloud
Products
desktop
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.