Improper input validation in Nextcloud Server - CVE-2018-3761
Published: August 6, 2018 / Updated: August 7, 2018
Nextcloud Server
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to insufficient input validation. A remote attacker with access to the OAuth2 refresh token can trick the victim into opening a specially crafted data and obtain new tokens.