Microsoft · Internet Explorer · CVE-2020-8294
Name of the Vulnerable Software and Affected Versions:
Nextcloud Server versions prior to 20.0.2
Nextcloud Server versions prior to 19.0.5
Nextcloud Server versions prior to 18.0.11
Description:
A missing link validation allows execution of a stored XSS attack when saving a 'javascript:' URL in markdown format using Internet Explorer.
Recommendations:
For versions prior to 20.0.2, update to version 20.0.2 or later.
For versions prior to 19.0.5, update to version 19.0.5 or later.
For versions prior to 18.0.11, update to version 18.0.11 or later.