ZeroHour

CVE-2024-37317

CVSS 3.1
4.6 medium
EPSS
<1%p24
Published
()
Modified
Description

The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the Nextcloud Notes app is upgraded to 4.9.3.

Vendors
nextcloud
Products
notes
Weakness
CWE-284, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.