CVE-2018-3763: XSS
Published Jul 5, 2018
·Updated
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.
Affected Software
2 affected components
Nextcloud calendar<1.5.8
Nextcloud calendar=1.6.0
Event History
Jul 5, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-3763.
2
What is the severity of CVE-2018-3763?
The severity of CVE-2018-3763 is medium, with a severity value of 4.8.
3
How does CVE-2018-3763 affect Nextcloud Calendar?
CVE-2018-3763 affects Nextcloud Calendar versions before 1.5.8 and 1.6.1.
4
What is the impact of CVE-2018-3763?
CVE-2018-3763 can lead to stored XSS (Cross-Site Scripting) attacks requiring user-interaction.
5
How can the vulnerability in Nextcloud Calendar be fixed?
To fix the vulnerability in Nextcloud Calendar, users should update to version 1.5.8 or 1.6.1.