Authentication Bypass Vulnerability in Nextcloud Server
CVE-2019-15617
5.4MEDIUM
What is CVE-2019-15617?
A vulnerability in Nextcloud Server 17.0.0 arises from a missing validation check, enabling unauthorized users to add an alternative second factor during the login process. This flaw poses a risk of account takeover, as attackers can exploit it to gain access to sensitive data without proper authorization. Organizations using this version of Nextcloud Server should take immediate measures to mitigate this risk by updating to patched versions.
Affected Version(s)
Nextcloud Server 17.0.1