First published: Wed Aug 07 2019(Updated: )
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Lookup-Server | <0.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5476 is an SQL Injection vulnerability in the Nextcloud Lookup-Server < v0.3.0, which allows unauthenticated users to execute arbitrary SQL commands.
The severity of CVE-2019-5476 is critical with a CVSS score of 9.8.
CVE-2019-5476 allows unauthenticated users to execute arbitrary SQL commands on Nextcloud Lookup-Server < v0.3.0.
To fix CVE-2019-5476, upgrade your Nextcloud Lookup-Server to version 0.3.0 or higher.
You can find more information about CVE-2019-5476 at the following link: https://hackerone.com/reports/508487.