Security Advisory

CVE-2017-0890

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-05-08 20:00:00
Last updated 2024-08-05 13:18:06
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.