First published: Mon Jun 08 2020(Updated: )
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud talk | <6.0.5 | |
Nextcloud talk | >=7.0.0<7.0.3 | |
Nextcloud talk | >=8.0.0<8.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-8180.
The severity of CVE-2020-8180 is critical.
Nextcloud Talk versions 6.0.4, 7.0.2, 7.0.0 to 7.0.3, 8.0.0 to 8.0.7, and 8.0.0 to 8.0.7 are affected by CVE-2020-8180.
The CWE ID for CVE-2020-8180 is 94.
To fix CVE-2020-8180, it is recommended to update Nextcloud Talk to version 6.0.5, 7.0.4, or 8.0.8 or later.