Stored XSS Vulnerability in Nextcloud Contacts Plugin
CVE-2018-3764
4.8MEDIUM
What is CVE-2018-3764?
A stored Cross-Site Scripting (XSS) vulnerability exists in the Nextcloud Contacts application prior to version 2.1.2. This vulnerability arises from inadequate sanitization of search results for an autocomplete field, specifically impacting group names. As a result, malicious search results can be generated by users with elevated privileges, such as administrators or group admins, leading to potential exploitation that requires user interaction.
Affected Version(s)
Nextcloud Contacts application <2.1.2