CVE-2017-0888: Input Validation
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0888?
CVE-2017-0888 is classified as a medium severity vulnerability due to its potential for content spoofing.
How do I fix CVE-2017-0888?
To fix CVE-2017-0888, upgrade Nextcloud Server to version 9.0.55 or later, or 10.0.2 or later.
What versions are affected by CVE-2017-0888?
CVE-2017-0888 affects Nextcloud Server versions before 9.0.55 and 10.0.2.
What type of vulnerability is CVE-2017-0888?
CVE-2017-0888 is a content spoofing vulnerability that allows for misrepresentation of information in the Nextcloud files app.
Can CVE-2017-0888 be exploited by users?
Yes, CVE-2017-0888 can be exploited by users with partial control over the input, potentially leading to content spoofing.