PT-2020-19988 · Nextcloud · Groupfolders

Francesco Moro

+1

·

Published

2020-05-12

·

Updated

2022-05-24

·

CVE-2020-8153

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Groupfolders app version 4.0.3
Description The issue is related to improper access control, allowing unauthorized deletion of hidden directories. This occurs when renaming an accessible item to the same name as a hidden directory in the Groupfolders app.
Recommendations For version 4.0.3, update to a newer version that addresses the improper access control issue to prevent unauthorized deletion of hidden directories.

Exploit

Fix

Improper Access Control

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8153

Affected Products

Groupfolders