Lucene search

K
hackeroneLourcodeH1:2307625
HistoryJan 08, 2024 - 9:26 a.m.

Nextcloud: Code injection in Nextcloud Desktop Client for macOS

2024-01-0809:26:44
lourcode
hackerone.com
$250
8
nextcloud
code injection
macos
security advisory
bug bounty

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.0%

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

AI Score

6.9

Confidence

High

EPSS

0

Percentile

5.0%