PT-2018-16194 · Nextcloud+1 · Nextcloud Server+1

Zhouyuan Yang

·

Published

2017-09-21

·

Updated

2023-02-28

·

CVE-2018-3776

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server versions prior to 12.0.3 Nextcloud Server versions prior to 11.0.5
Description The issue is related to an improper input validator, which could allow an attacker's actions to remain unlogged in the audit log.
Recommendations For versions prior to 12.0.3, update to version 12.0.3 or later. For versions prior to 11.0.5, update to version 11.0.5 or later.

Fix

RCE

Insertion into Log File

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2277
CVE-2018-3776

Affected Products

Alt Linux
Nextcloud Server