Cross-site scripting in Nextcloud Server - CVE-2019-15619
Published: February 4, 2020 / Updated: July 17, 2020
Vulnerability identifier: #VU30391
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2019-15619
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to read and manipulate data.
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
Affected software
Nextcloud Server
How to mitigate CVE-2019-15619
Install update from vendor's website.
Nextcloud Server - update to 16.0.4