CVE-2019-15618: XSS
Published Feb 4, 2020
·Updated
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
Affected Software
2 affected components
Nextcloud Server<14.0.9
Nextcloud Server>=15.0.0<15.0.6
Event History
Feb 4, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-15618?
CVE-2019-15618 is considered to have a medium severity level due to its reflected XSS vulnerability.
2
How do I fix CVE-2019-15618?
To fix CVE-2019-15618, update Nextcloud to version 15.0.6 or later.
3
Which versions of Nextcloud are affected by CVE-2019-15618?
CVE-2019-15618 affects Nextcloud versions 15.0.0 to 15.0.5 and all versions up to 14.0.9.
4
What kind of vulnerability is CVE-2019-15618?
CVE-2019-15618 is a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2019-15618 be exploited remotely?
Yes, CVE-2019-15618 can be exploited remotely if an attacker tricks a user into accessing a malicious link while using the updater.