Nextcloud · Nextcloud Server · CVE-2017-0890
**Name of the Vulnerable Software and Affected Versions**
Nextcloud Server versions prior to 11.0.3
**Description**
The issue is related to inadequate escaping, leading to a XSS vulnerability in the search module. A user must write or paste malicious content into the search dialogue for it to be exploitable.
**Recommendations**
For versions prior to 11.0.3, update to version 11.0.3 or later to resolve the issue. As a temporary workaround, consider restricting user input in the search dialogue to minimize the risk of exploitation.