Lucene search

K
cvelistHackeroneCVELIST:CVE-2019-15619
HistoryFeb 04, 2020 - 7:08 p.m.

CVE-2019-15619

2020-02-0419:08:57
CWE-79
hackerone
www.cve.org

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.7%

Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.

CNA Affected

[
  {
    "product": "Nextcloud Server",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "16.0.4"
      }
    ]
  }
]

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.7%