#VU63483 Improper access control in Nextcloud Android App - CVE-2022-29160
Published: May 20, 2022
Vulnerability identifier: #VU63483
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-29160
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Nextcloud Android App
Nextcloud Android App
Software vendor:
Nextcloud
Nextcloud
Description
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the information can be misused as sensitive token, images and user related details exist despite of user account being deleted. A local user can gain access to sensitive information on the system
Remediation
Install updates from vendor's website.