First published: Fri Jul 10 2020(Updated: )
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Contacts | <3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-8181 is medium with a severity value of 4.3.
CVE-2020-8181 allows a malicious user to upload any file as avatars in Nextcloud Contacts 3.2.0.
Nextcloud Contacts versions up to exclusive 3.3.0 are affected by CVE-2020-8181.
To fix CVE-2020-8181, it is recommended to update Nextcloud Contacts to a version beyond 3.3.0.
The Common Weakness Enumeration (CWE) IDs for CVE-2020-8181 are 434 and 840.