Cross-site scripting in Nextcloud Server - CVE-2019-15619

 

Cross-site scripting in Nextcloud Server - CVE-2019-15619

Published: February 4, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30391
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2019-15619
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to read and manipulate data.

Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.


Affected software

Nextcloud Server

How to mitigate CVE-2019-15619

Install update from vendor's website.

Nextcloud Server - update to 16.0.4

External References

Related Security Bulletins