CVE-2021-22879

Publication date

2021-04-14 12:41:24

Family

hackerone

State

PUBLISHED

Description

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.