CVE-2021-32733: XSS in Nextcloud Text application
Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13, 20.0.11, and 21.0.3. The Nextcloud Text application shipped with Nextcloud server used a text/html Content-Type when serving files to users. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. As a workaround, use a browser that has support for Content-Security-Policy.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32733?
CVE-2021-32733 is classified as a cross-site scripting (XSS) vulnerability with a medium severity level.
How do I fix CVE-2021-32733?
To fix CVE-2021-32733, upgrade Nextcloud Text to versions 19.0.13, 20.0.11, or 21.0.3 or later.
Which versions of Nextcloud Server are affected by CVE-2021-32733?
CVE-2021-32733 affects Nextcloud Server versions prior to 19.0.13, 20.0.11, and 21.0.3.
What type of vulnerability is CVE-2021-32733?
CVE-2021-32733 is a cross-site scripting (XSS) vulnerability in the Nextcloud Text application.
Is user data at risk due to CVE-2021-32733?
Yes, CVE-2021-32733 could potentially allow attackers to execute malicious scripts in the context of the user's session.