4.7 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
22.7%
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
hackerone.com/reports/515484
nextcloud.com/security/advisory/?id=NC-SA-2020-007