Input validation error in Nextcloud Server - CVE-2019-15624
Published: February 4, 2020 / Updated: July 17, 2020
Vulnerability identifier: #VU30394
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15624
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to manipulate data.
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
Affected software
Nextcloud Server
How to mitigate CVE-2019-15624
Install update from vendor's website.
Nextcloud Server - update to 15.0.8