Input validation error in nextcloud - CVE-2017-0888
Published: April 5, 2017 / Updated: August 8, 2020
nextcloud
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.