← back
CVE-2018-3781

CVE-2018-3781

EPSS 0.6%CWE-79
A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →