Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hitman_47

#47181of 53,624
5.4Total CVSS
Vulnerabilities · 1
PT-2021-12717
5.4
2021-01-06
Nextcloud · Nextcloud Contacts · CVE-2020-8280
Name of the Vulnerable Software and Affected Versions: Nextcloud Contacts version 3.4.0 Description: A missing file type check allows a malicious user to upload SVG files as PNG files, enabling cross-site scripting (XSS) attacks. Recommendations: For Nextcloud Contacts version 3.4.0, consider restricting the upload of SVG files or implementing a proper file type check to prevent cross-site scripting attacks until a patch is available.