Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vmj-qqqc-grm3

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

EPSS

Процентиль: 77%
0.01045
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284
CWE-451

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

CVSS3: 5.3
nvd
около 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

CVSS3: 5.3
debian
около 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0 ...

EPSS

Процентиль: 77%
0.01045
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284
CWE-451