CVE-2019-12739

Publication date

2019-06-05 13:57:32

Family

mitre

State

PUBLISHED

Description

lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).