Input validation error in Nextcloud Server - CVE-2019-15624

 

Input validation error in Nextcloud Server - CVE-2019-15624

Published: February 4, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30394
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15624
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to manipulate data.

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.


Affected software

Nextcloud Server

How to mitigate CVE-2019-15624

Install update from vendor's website.

Nextcloud Server - update to 15.0.8

External References

Related Security Bulletins