First published: Tue Feb 04 2020(Updated: )
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud | <3.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15622 is a vulnerability in the Nextcloud Android app 3.6.0 that allowed an attacker to access content information from protected tables using custom queries.
CVE-2019-15622 affects Nextcloud Android app 3.6.0 and earlier versions.
The severity of CVE-2019-15622 is low with a CVSS score of 2.4.
To fix CVE-2019-15622, update your Nextcloud Android app to version 3.6.1 or later.
You can find more information about CVE-2019-15622 in the following references: [HackerOne Report](https://hackerone.com/reports/518669), [Nextcloud Advisory](https://nextcloud.com/security/advisory/?id=NC-SA-2019-011).