Описание
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.6.1 (исключая)
cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00337
Низкий
4.6 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.6
ubuntu
около 3 лет назад
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.
CVSS3: 4.6
debian
около 3 лет назад
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker ...
EPSS
Процентиль: 56%
0.00337
Низкий
4.6 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79