CVE-2020-8189: XSS
Published Aug 21, 2020
·Updated
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
Affected Software
1 affected component
Nextcloud Desktop<2.6.5
Event History
Aug 21, 2020
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-8189?
CVE-2020-8189 is a cross-site scripting vulnerability in the Nextcloud Desktop client 2.6.4.
2
What is the severity of CVE-2020-8189?
The severity of CVE-2020-8189 is medium, with a CVSS score of 5.4.
3
How does CVE-2020-8189 affect Nextcloud Desktop?
CVE-2020-8189 allows an attacker to present any HTML, including local links, when responding with invalid data on the login attempt in Nextcloud Desktop client 2.6.4.
4
How can I fix CVE-2020-8189?
To fix CVE-2020-8189, upgrade Nextcloud Desktop client to version 2.6.5 or newer.
5
Where can I find more information about CVE-2020-8189?
You can find more information about CVE-2020-8189 on the Nextcloud security advisory page, HackerOne report, and Gentoo advisory.