CVE-2019-15622: SQL Injection
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15622?
CVE-2019-15622 is a vulnerability in the Nextcloud Android app 3.6.0 that allowed an attacker to access content information from protected tables using custom queries.
How does CVE-2019-15622 affect Nextcloud?
CVE-2019-15622 affects Nextcloud Android app 3.6.0 and earlier versions.
What is the severity of CVE-2019-15622?
The severity of CVE-2019-15622 is low with a CVSS score of 2.4.
How can I fix CVE-2019-15622 in my Nextcloud Android app?
To fix CVE-2019-15622, update your Nextcloud Android app to version 3.6.1 or later.
Where can I find more information about CVE-2019-15622?
You can find more information about CVE-2019-15622 in the following references: [HackerOne Report](https://hackerone.com/reports/518669), [Nextcloud Advisory](https://nextcloud.com/security/advisory/?id=NC-SA-2019-011).