Nextcloud · Nextcloud Lookup-Server · CVE-2019-5476
**Name of the Vulnerable Software and Affected Versions**
Nextcloud Lookup-Server versions prior to 0.3.0
**Description**
The issue allows unauthenticated users to execute arbitrary SQL commands due to an SQL Injection. This affects the Nextcloud Lookup-Server running on https://lookup.nextcloud.com.
**Recommendations**
For versions prior to 0.3.0, update to version 0.3.0 or later to resolve the issue.