Lucene search

K
hackeroneMikeisastarH1:1668028
HistoryAug 12, 2022 - 7:00 p.m.

Nextcloud: XSS in Desktop Client in the notifications

2022-08-1219:00:00
mikeisastar
hackerone.com
$750
16
nextcloud
desktop client
xss
windows 10
notification
security
bug bounty

EPSS

0.001

Percentile

26.4%

Summary:

The Nextcloud Desktop Client application does not properly neutralize the names of files before using them.

Steps To Reproduce:

Server Machine

  1. Install the Nextcloud Server application
  2. Log into your account

Client Machine

  1. Install the Nextcloud Desktop Client application onto a machine that is running the Windows 10 operating system
  2. Log into your account

Server Machine

  1. Upload any file to your Nextcloud Server instance
  2. Rename the file that you uploaded to <h1><b><i><u>MikeIsAStar

Client Machine

  1. Wait until a notification appears exclaiming that some files could not synchronized
  2. Open the main dialog window of the Nextcloud Desktop Client application
  3. Observe that the name of the file that you uploaded is treated as HyperText Markup Language

Supporting Material/References:

{F1864812}

Impact

An attacker can inject arbitrary HyperText Markup Language into the Nextcloud Desktop Client application.