← back
CVE-2018-3780

CVE-2018-3780

EPSS 0.8%CWE-79
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →