An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
2020-05-12T13:15:13.063
2024-11-21T05:38:23.883
Modified
CVSSv3.1: 7.7 (HIGH)
AV:N/AC:L/Au:S/C:N/I:N/A:C
8.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nextcloud | nextcloud_server | < 17.0.5 | Yes |
Application | nextcloud | nextcloud_server | < 18.0.3 | Yes |