Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.
References
Link | Resource |
---|---|
https://hackerone.com/reports/631227 | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-07-30 14:15
Updated : 2021-11-03 10:50
NVD link : CVE-2019-5450
Mitre link : CVE-2019-5450
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
nextcloud
- nextcloud