Описание
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in OC.Notification.show
.
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in OC.Notification.show
.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-22878
- https://github.com/nextcloud/server/pull/25234
- https://hackerone.com/reports/896522
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L6BO6P6MP2MOWA6PZRXX32PLWPXN5O4S
- https://nextcloud.com/security/advisory/?id=NC-SA-2021-005
Связанные уязвимости
CVSS3: 4.8
nvd
больше 4 лет назад
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
CVSS3: 4.8
debian
больше 4 лет назад
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site ...