CVE-2020-8181: Malicious File Upload
Published Jul 10, 2020
·Updated
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
Affected Software
1 affected component
Nextcloud Contacts<3.3.0
Remediation
Patch Available
Event History
Jul 10, 2020
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-8181?
The severity of CVE-2020-8181 is medium with a severity value of 4.3.
2
How does CVE-2020-8181 impact Nextcloud Contacts?
CVE-2020-8181 allows a malicious user to upload any file as avatars in Nextcloud Contacts 3.2.0.
3
Which versions of Nextcloud Contacts are affected by CVE-2020-8181?
Nextcloud Contacts versions up to exclusive 3.3.0 are affected by CVE-2020-8181.
4
How can I fix CVE-2020-8181?
To fix CVE-2020-8181, it is recommended to update Nextcloud Contacts to a version beyond 3.3.0.
5
What is the Common Weakness Enumeration ID for CVE-2020-8181?
The Common Weakness Enumeration (CWE) IDs for CVE-2020-8181 are 434 and 840.