CVE-2020-8235

Publication date

2020-10-05 13:16:08

Family

hackerone

State

PUBLISHED

Description

Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.