Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2020-08-21T20:33:44

Updated: 2024-08-04T09:56:27.442Z

Reserved: 2020-01-28T00:00:00

Link: CVE-2020-8227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-08-21T21:15:11.967

Modified: 2022-09-27T16:01:31.960

Link: CVE-2020-8227

cve-icon Redhat

No data.