Vulnerabilities
Vulnerable Software
Nextcloud:  >> Talk  >> 14.1.0  Security Vulnerabilities
Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud Talk Android version 17.0.0 has a patch for this issue. No known workarounds are available.
CVSS Score
7.2
EPSS Score
0.004
Published
2023-08-10
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.
CVSS Score
2.1
EPSS Score
0.0
Published
2023-01-09


Contact Us

Shodan ® - All rights reserved