Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2020-02-04T19:08:57

Updated: 2020-02-04T19:08:57

Reserved: 2019-08-26T00:00:00


Link: CVE-2019-15619

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-04T20:15:12.340

Modified: 2020-02-12T16:23:41.450


Link: CVE-2019-15619

JSON object: View

cve-icon Redhat Information

No data.

CWE