Stored XSS Vulnerability in Nextcloud Server by Nextcloud
CVE-2020-8294

5.4MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
3 February 2021

What is CVE-2020-8294?

A vulnerability in Nextcloud Server versions before 20.0.2, 19.0.5, and 18.0.11 due to missing link validation can lead to stored Cross-Site Scripting (XSS) attacks. Attackers can exploit this flaw by saving 'javascript:' URLs in markdown format, which may be executed by users accessing the affected content using Internet Explorer. This exposes users to potential exploitation of their data and the integrity of the application itself. It is crucial for Nextcloud administrators to update their instances to the latest versions to mitigate this risk.

Affected Version(s)

Nextcloud Server Fixed in 20.0.2, 19.0.5, 18.0.11

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.