Lucene search

K
nvd[email protected]NVD:CVE-2023-48302
HistoryNov 21, 2023 - 10:15 p.m.

CVE-2023-48302

2023-11-2122:15:07
CWE-79
web.nvd.nist.gov
5
nextcloud
html rendering
version 25.0.13
version 26.0.8
version 27.1.3
data storage
security issue
workaround

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

21.1%

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, when a user is tricked into copy pasting HTML code without markup (Ctrl+Shift+V) the markup will actually render. Nextcloud Server and Nextcloud Enterprise Server versions 25.0.13, 26.0.8, and 27.1.3 contain a fix for this issue. As a workaround, disable app text.

Affected configurations

Nvd
Node
nextcloudnextcloud_serverRange25.0.025.0.13-
OR
nextcloudnextcloud_serverRange25.0.025.0.13enterprise
OR
nextcloudnextcloud_serverRange26.0.026.0.8-
OR
nextcloudnextcloud_serverRange26.0.026.0.8enterprise
OR
nextcloudnextcloud_serverRange27.0.027.1.3-
OR
nextcloudnextcloud_serverRange27.0.027.1.3enterprise
VendorProductVersionCPE
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

21.1%