Vulnerability Name: | CVE-2019-15619 (CCN-175797) | ||||||||||||
Assigned: | 2019-07-26 | ||||||||||||
Published: | 2019-07-26 | ||||||||||||
Updated: | 2020-02-12 | ||||||||||||
Summary: | Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project. | ||||||||||||
CVSS v3 Severity: | 4.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-15619 Source: XF Type: UNKNOWN nextcloud-cve201915619-xss(175797) Source: MISC Type: Permissions Required https://hackerone.com/reports/662204 Source: CCN Type: NC-SA-2020-008 Improper neutralization of item names in projects feature Source: MISC Type: Vendor Advisory https://nextcloud.com/security/advisory/?id=NC-SA-2020-008 Source: MISC Type: Vendor Advisory https://nextcloud.com/security/advisory/?id=NC-SA-2020-009 Source: MISC Type: Vendor Advisory https://nextcloud.com/security/advisory/?id=NC-SA-2020-010 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |