CVE-2018-3781: XSS
A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3781?
CVE-2018-3781 has a medium severity level due to the potential for stored XSS attacks requiring user interaction.
What causes CVE-2018-3781?
CVE-2018-3781 is caused by a missing sanitization of search results for an autocomplete field in NextCloud Talk versions below 3.2.5.
How do I fix CVE-2018-3781?
To fix CVE-2018-3781, upgrade NextCloud Talk to version 3.2.5 or later.
Who is affected by CVE-2018-3781?
Authenticated users of NextCloud Talk versions below 3.2.5 are affected by CVE-2018-3781.
What type of vulnerability is CVE-2018-3781?
CVE-2018-3781 is classified as a stored cross-site scripting (XSS) vulnerability.