First published: Mon May 08 2017(Updated: )
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Server | <9.0.58 | |
Nextcloud Server | >=10.0.0<10.0.5 | |
Nextcloud Server | >=11.0.0<11.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0891 has a medium severity rating due to its potential for leading to XSS vulnerabilities.
To fix CVE-2017-0891, update your Nextcloud Server to version 9.0.58 or higher, 10.0.5 or higher, or 11.0.3 or higher.
CVE-2017-0891 affects Nextcloud Server versions before 9.0.58, 10.0.5, and 11.0.3.
CVE-2017-0891 is classified as an inadequate escaping of error messages leading to cross-site scripting (XSS) vulnerabilities.
Yes, CVE-2017-0891 can be exploited remotely, making it critical for affected users to apply the necessary updates.