CVE-2018-3764: XSS
Published Jul 5, 2018
·Updated
In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.
Affected Software
1 affected component
Nextcloud Contacts<2.1.2
Event History
Jul 5, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Nextcloud Contacts vulnerability?
The vulnerability ID for this Nextcloud Contacts vulnerability is CVE-2018-3764.
2
What is the severity of CVE-2018-3764?
The severity of CVE-2018-3764 is medium with a CVSS score of 4.8.
3
What is the affected software for CVE-2018-3764?
The affected software for CVE-2018-3764 is Nextcloud Contacts before version 2.1.2.
4
What is the description of CVE-2018-3764?
CVE-2018-3764 is a vulnerability in Nextcloud Contacts before 2.1.2 that allows a stored XSS attack requiring user interaction.
5
Is there a fix available for CVE-2018-3764?
Yes, the fix for CVE-2018-3764 is available in Nextcloud Contacts version 2.1.2.