Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-22472

Опубликовано: 09 янв. 2023
Источник: nvd
CVSS3: 5.3
CVSS3: 8.8
EPSS Низкий

Описание

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST request with an arbitrary body given they click on a malicious deep link on a Windows computer. (e.g. in an email, chat link, etc). There are currently no known workarounds. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nextcloud:desktop:3.6.1:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00293
Низкий

5.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-352
CWE-352

EPSS

Процентиль: 52%
0.00293
Низкий

5.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-352
CWE-352