← Back

CVE-2019-15619

nvd nist
Published: Feb 4, 2020Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.

Affected (3)

3 products
Deck
Nextcloud Server
Talk
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.6.6
Before 16.0.4
Before 6.0.4

References (8)

Source: support@hackerone.com
Permissions Required
Source: support@hackerone.com
Vendor Advisory
Source: support@hackerone.com
Vendor Advisory
Source: support@hackerone.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.