Description
In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-15570 | In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins. |
References
| Link | Providers |
|---|---|
| https://nextcloud.com/security/advisory/?id=nc-sa-2018-005 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-05T04:50:30.571Z
Reserved: 2017-12-28T00:00:00.000Z
Link: CVE-2018-3764
No data.
Status : Modified
Published: 2018-07-05T16:29:00.563
Modified: 2024-11-21T04:06:02.020
Link: CVE-2018-3764
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD