← back
CVE-2024-22213noneCWE-79

Cross-site Scripting when sending HTML as a comment in the Nextcloud Deck app

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 0epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N