CVE-2019-5476: SQL Injection
Published Aug 7, 2019
·Updated
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.
Affected Software
1 affected component
Nextcloud Lookup-Server<0.3.0
Event History
Aug 7, 2019
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-5476?
CVE-2019-5476 is an SQL Injection vulnerability in the Nextcloud Lookup-Server < v0.3.0, which allows unauthenticated users to execute arbitrary SQL commands.
2
What is the severity of CVE-2019-5476?
The severity of CVE-2019-5476 is critical with a CVSS score of 9.8.
3
How does CVE-2019-5476 affect Nextcloud Lookup-Server?
CVE-2019-5476 allows unauthenticated users to execute arbitrary SQL commands on Nextcloud Lookup-Server < v0.3.0.
4
How can I fix CVE-2019-5476?
To fix CVE-2019-5476, upgrade your Nextcloud Lookup-Server to version 0.3.0 or higher.
5
Where can I find more information about CVE-2019-5476?
You can find more information about CVE-2019-5476 at the following link: https://hackerone.com/reports/508487.