Описание
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource inje ...
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
EPSS
8.8 High
CVSS3
6.8 Medium
CVSS2