First published: Mon Feb 06 2023(Updated: )
The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior to 3.6.3 are missing sanitisation on qml labels which are used for basic HTML elements such as `strong`, `em` and `head` lines in the UI of the desktop client. The lack of sanitisation may allow for javascript injection. It is recommended that the Nextcloud Desktop Client is upgraded to 3.6.3. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Desktop | <3.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-23942.
The severity of CVE-2023-23942 is medium with a CVSS score of 6.1.
The Nextcloud Desktop Client versions prior to 3.6.3 are affected by CVE-2023-23942.
CVE-2023-23942 impacts the Nextcloud Desktop Client by allowing HTML injection in the UI of the desktop client.
To fix CVE-2023-23942, it is recommended to update the Nextcloud Desktop Client to version 3.6.3 or later.