Логотип exploitDog
product: "nextcloud_server"
Консоль
Логотип exploitDog

exploitDog

product: "nextcloud_server"

Количество 413

Количество 413

github логотип

GHSA-r63f-25g5-v4wf

больше 3 лет назад

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

EPSS: Низкий
github логотип

GHSA-qxf8-5jgm-xwxj

больше 3 лет назад

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-qv8x-gg84-8259

больше 3 лет назад

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-pv3c-r8vx-j8wm

больше 3 лет назад

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-pqcg-83hr-mr43

больше 3 лет назад

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

EPSS: Низкий
github логотип

GHSA-mwjc-vmmg-j6vm

больше 3 лет назад

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-mr7g-84h2-qmm4

больше 3 лет назад

A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.

EPSS: Низкий
github логотип

GHSA-mqg9-fwrm-2gxr

больше 3 лет назад

A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mjfh-rmmm-2mm7

больше 3 лет назад

A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.

EPSS: Низкий
github логотип

GHSA-mc2j-762j-c5hj

больше 3 лет назад

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-m9wc-h684-m6rq

больше 3 лет назад

A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.

EPSS: Низкий
github логотип

GHSA-jg28-fqcj-8vhj

больше 3 лет назад

A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-jchm-73f8-w72j

больше 3 лет назад

Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.

EPSS: Низкий
github логотип

GHSA-j92w-qfjr-c5j9

больше 3 лет назад

A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-grrj-5c92-774h

больше 3 лет назад

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-g8q5-cq4v-2qq7

больше 3 лет назад

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-g265-v379-5vwj

больше 3 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-fxf7-m32w-qh93

больше 3 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fw6c-8m99-2qjj

больше 3 лет назад

A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-frc3-rhfw-jxf5

больше 3 лет назад

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-r63f-25g5-v4wf

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-qxf8-5jgm-xwxj

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-qv8x-gg84-8259

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pv3c-r8vx-j8wm

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-pqcg-83hr-mr43

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mwjc-vmmg-j6vm

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mr7g-84h2-qmm4

A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mqg9-fwrm-2gxr

A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mjfh-rmmm-2mm7

A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mc2j-762j-c5hj

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-m9wc-h684-m6rq

A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-jg28-fqcj-8vhj

A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-jchm-73f8-w72j

Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-j92w-qfjr-c5j9

A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.

CVSS3: 5.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-grrj-5c92-774h

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-g8q5-cq4v-2qq7

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-g265-v379-5vwj

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fxf7-m32w-qh93

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fw6c-8m99-2qjj

A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-frc3-rhfw-jxf5

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу