Lucene search

K
nextcloudNextcloudGHSA-P7G9-X25M-4H87
HistoryNov 21, 2023 - 5:24 a.m.

Self XSS when pasting HTML into Text app with Ctrl+Shift+V

2023-11-2105:24:35
github.com
15
nextcloud
upgrade
security
vulnerability
html
xss
nextcloud server
nextcloud enterprise
disable app text

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

21.1%

Description

Impact

When a user is tricked into copy pasting HTML code without markup (Ctrl+Shift+V) the markup will actually render.

Patches

It is recommended that the Nextcloud Server is upgraded to 25.0.13, 26.0.8 or 27.1.3
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.13, 26.0.8 or 27.1.3

Workarounds

  • Disable app text

References

For more information

If you have any questions or comments about this advisory:

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

21.1%