Impact
The vulnerability arises because the emoji field in the page emoji update endpoint does not enforce proper input validation. By sending a payload comprising long text and line breaks, an attacker can corrupt the sidebar layout, causing visual elements to move or become hidden. This flaw falls under an input validation weakness (CWE‑840). While it does not lead to data loss or unauthorized access, the resulting UI disruption can affect user experience and potentially conceal critical interface components.
Affected Systems
The flaw affects the Nextcloud Collectives app. No specific version numbers are provided in the data, so any installation of Collectives running the affected endpoint without the proper validation fix is at risk.
Risk and Exploitability
The CVSS score of 2.4 indicates low severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity so far. The attack vector is likely remote via authenticated web requests to the emoji update endpoint. An attacker with write access to emojis could use this to cause UI distortion for other users, but the impact remains modest and primarily cosmetic.
OpenCVE Enrichment