Cross-Site Scripting Vulnerability in Nextcloud Contacts by Nextcloud
CVE-2020-8281
5.4MEDIUM
What is CVE-2020-8281?
A vulnerability in Nextcloud Contacts version 3.3.0 enables attackers to upload harmful SVG files due to inadequate file type validation. This insufficiency permits malicious users to execute cross-site scripting (XSS) attacks, potentially compromising user data and the overall security of the application.
Affected Version(s)
Nextcloud Contacts Fixed in 3.4.0