lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-06-05T13:57:32

Updated: 2024-08-04T23:32:54.186Z

Reserved: 2019-06-05T00:00:00

Link: CVE-2019-12739

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-05T14:29:11.513

Modified: 2019-06-06T23:29:00.243

Link: CVE-2019-12739

cve-icon Redhat

No data.