First published: Tue Jul 30 2019(Updated: )
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud | <3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-5450.
The affected software is the Nextcloud Android app prior to version 3.7.0.
The severity of CVE-2019-5450 is medium.
This vulnerability allows the styling of directory names in the header bar when using basic HTML.
To fix CVE-2019-5450, update the Nextcloud Android app to version 3.7.0 or later.