Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32782

Опубликовано: 07 сент. 2021
Источник: nvd
CVSS3: 5.8
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy. It is recommended that the Nextcloud Circles application is upgraded to 0.21.3, 0.20.10 or 0.19.14 to resolve this issue. As a workaround users may use a browser that has support for Content-Security-Policy. A notable exemption is Internet Explorer which does not support CSP properly.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nextcloud:circles:*:*:*:*:*:*:*:*
Версия до 0.19.14 (исключая)
cpe:2.3:a:nextcloud:circles:*:*:*:*:*:*:*:*
Версия от 0.20.0 (включая) до 0.20.10 (исключая)
cpe:2.3:a:nextcloud:circles:*:*:*:*:*:*:*:*
Версия от 0.21.0 (включая) до 0.21.3 (исключая)

EPSS

Процентиль: 58%
0.00358
Низкий

5.8 Medium

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

EPSS

Процентиль: 58%
0.00358
Низкий

5.8 Medium

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79