ZeroHour

CVE-2020-8235

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p54
Published
()
Modified
Description

Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

Vendors
nextcloud
Products
deck
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.