First published: Tue Feb 04 2020(Updated: )
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud | <2.25.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15614 is a vulnerability that occurs in the iOS App 2.24.4 and allows for cross-site scripting (XSS) attacks when opening malicious HTML files.
CVE-2019-15614 has a severity keyword of 'medium' and a severity value of 5.4.
CVE-2019-15614 affects Nextcloud iOS App versions up to and excluding 2.25.0.
To fix CVE-2019-15614, upgrade your Nextcloud iOS App to version 2.25.0 or higher.
For more information about CVE-2019-15614, you can refer to the following sources: [HackerOne report](https://hackerone.com/reports/575562) and [Nextcloud Security Advisory](https://nextcloud.com/security/advisory/?id=NC-SA-2020-003).