CVE-2017-0890

Publication date

2017-05-08 20:00:00

Family

hackerone

State

PUBLISHED

Description

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.