CVE-2023-39955: Notes attachment render HTML in preview mode
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-39955?
CVE-2023-39955 is a vulnerability in the Notes app for Nextcloud, versions 4.4.0 to 4.8.0, that allows HTML content to be rendered in the preview instead of being offered for download.
How does CVE-2023-39955 affect Nextcloud Notes app?
CVE-2023-39955 affects Nextcloud Notes app versions 4.4.0 to 4.8.0, allowing HTML content to be rendered in the preview instead of being offered for download.
What is the severity of CVE-2023-39955?
CVE-2023-39955 has a severity of medium with a CVSS score of 6.1.
How can I fix CVE-2023-39955?
To fix CVE-2023-39955, update your Nextcloud Notes app to version 4.8.0 or later.
Where can I find more information about CVE-2023-39955?
You can find more information about CVE-2023-39955 on the Nextcloud Notes GitHub repository, Nextcloud security advisories, and HackerOne report.