CVE-2019-15614: XSS
Published Feb 4, 2020
·Updated
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
Affected Software
1 affected component
Nextcloud Nextcloud Iphone Os<2.25.0
Event History
Feb 4, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-15614?
CVE-2019-15614 is a vulnerability that occurs in the iOS App 2.24.4 and allows for cross-site scripting (XSS) attacks when opening malicious HTML files.
2
How severe is CVE-2019-15614?
CVE-2019-15614 has a severity keyword of 'medium' and a severity value of 5.4.
3
Which software versions are affected by CVE-2019-15614?
CVE-2019-15614 affects Nextcloud iOS App versions up to and excluding 2.25.0.
4
How can I fix CVE-2019-15614?
To fix CVE-2019-15614, upgrade your Nextcloud iOS App to version 2.25.0 or higher.
5
Where can I find more information about CVE-2019-15614?
For more information about CVE-2019-15614, you can refer to the following sources: [HackerOne report](https://hackerone.com/reports/575562) and [Nextcloud Security Advisory](https://nextcloud.com/security/advisory/?id=NC-SA-2020-003).