CVE-2024-22213: Cross-site Scripting when sending HTML as a comment in the Nextcloud Deck app
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud Deckto a version that resolves this vulnerability.Fixed in 1.9.5 - Upgrade
Upgrade
Nextcloud Deckto a version that resolves this vulnerability.Fixed in 1.11.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22213?
CVE-2024-22213 has been classified with a severity that indicates a risk of remote code execution through malicious comments.
How do I fix CVE-2024-22213?
To fix CVE-2024-22213, upgrade Nextcloud Deck to versions 1.9.6 or 1.11.3 or later.
What versions of Nextcloud Deck are affected by CVE-2024-22213?
CVE-2024-22213 affects Nextcloud Deck versions between 1.9.0 and 1.9.5, and 1.10.0 and 1.11.2.
Can CVE-2024-22213 lead to data breaches?
Yes, CVE-2024-22213 can potentially lead to data breaches as it allows execution of malicious scripts in users' browsers.
How does CVE-2024-22213 exploit occur?
CVE-2024-22213 exploits occur when a user is tricked into executing malicious HTML code embedded in comments.