Vulnerabilities
Vulnerable Software
Nextcloud:  >> Nextcloud  >> 1.7.0  Security Vulnerabilities
Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-06-11
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.
CVSS Score
4.3
EPSS Score
0.005
Published
2017-04-05
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.
CVSS Score
5.3
EPSS Score
0.005
Published
2017-03-28


Contact Us

Shodan ® - All rights reserved