First published: Wed Mar 03 2021(Updated: )
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | <20.0.6 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22878 is a vulnerability in Nextcloud Server prior to version 20.0.6 that allows for reflected cross-site scripting (XSS) attacks.
CVE-2021-22878 allows an attacker to execute malicious scripts in the victim's browser, potentially leading to unauthorized actions or data theft.
CVE-2021-22878 has a severity rating of medium with a CVSS score of 4.8.
To fix CVE-2021-22878, it is recommended to update Nextcloud Server to version 20.0.6 or later.
You can find more information about CVE-2021-22878 at the following references: [GitHub Pull Request](https://github.com/nextcloud/server/pull/25234) and [HackerOne report](https://hackerone.com/reports/896522).