Lucene search

K
hackeroneNickvergessenH1:1390331
HistoryNov 03, 2021 - 7:38 a.m.

Nextcloud: SQL injextion via vulnerable doctrine/dbal version

2021-11-0307:38:44
nickvergessen
hackerone.com
44

0.002 Low

EPSS

Percentile

53.6%

Summary:

SQL injection via limit parameter on user facing APIs

Steps To Reproduce:

Run security scanner:

  1. REPORT /remote.php/dav/comments/files/1985
  2. XML input oc:filter-comments.oc:limit#text was set to 1’"
  3. You have an error in your SQL syntax

Supporting Material/References:

For more details see:
https://github.com/nextcloud-gmbh/h1/issues/197

Impact

Full flexed SQL injection via user provided input