Lucene search

K
nextcloudNextcloudGHSA-WGPW-QQQ2-GWV6
HistoryNov 21, 2023 - 5:27 a.m.

HTML injection in search UI when selecting a circle with HTML in the display name

2023-11-2105:27:00
github.com
13
html injection
search ui
nextcloud server
nextcloud enterprise
circles
upgrade
security advisory

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

20.0%

Description

Impact

An attacker could insert links into circles name that would be opened when clicking the circle name in a search filter.

Patches

It is recommended that the Nextcloud Server is upgraded to 25.0.13, 26.0.8 or 27.1.3
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.13, 26.0.8 or 27.1.3

Workarounds

  • Disable app circles

References

For more information

If you have any questions or comments about this advisory:

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

20.0%