Stored XSS Vulnerability in Nextcloud Contacts Plugin
CVE-2018-3764

4.8MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
5 July 2018

What is CVE-2018-3764?

A stored Cross-Site Scripting (XSS) vulnerability exists in the Nextcloud Contacts application prior to version 2.1.2. This vulnerability arises from inadequate sanitization of search results for an autocomplete field, specifically impacting group names. As a result, malicious search results can be generated by users with elevated privileges, such as administrators or group admins, leading to potential exploitation that requires user interaction.

Affected Version(s)

Nextcloud Contacts application <2.1.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-3764 : Stored XSS Vulnerability in Nextcloud Contacts Plugin