Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vmj-qqqc-grm3

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

EPSS

Процентиль: 78%
0.01151
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284
CWE-451

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

CVSS3: 5.3
nvd
больше 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

CVSS3: 5.3
debian
больше 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0 ...

EPSS

Процентиль: 78%
0.01151
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284
CWE-451