Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
2020-08-21T21:15:11.967
2024-11-21T05:38:32.633
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:N/AC:H/Au:S/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nextcloud | desktop | < 2.6.5 | Yes |
Operating System | linux | linux_kernel | - | No |