Lucene search

K
nextcloudNikita TikhomirovNC-SA-2020-007
HistoryMar 26, 2019 - 12:00 a.m.

Reflected XSS in redirect of the Updater (NC-SA-2020-007)

2019-03-2600:00:00
Nikita Tikhomirov
nextcloud.com
10

0.001 Low

EPSS

Percentile

22.7%

Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.

0.001 Low

EPSS

Percentile

22.7%