ZeroHour

CVE-2021-22905

PoC
CVSS 3.1
6.5 medium
EPSS
1%p70
Published
()
Modified
Description

Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by the user.

Vendors
nextcloud
Products
nextcloud
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.