PT-2020-20077 · Nextcloud · Nextcloud Social App
Published
2020-11-19
·
Updated
2020-12-02
·
CVE-2020-8278
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Social app version 0.3.1
Description
The issue is related to improper access control, which allows reading posts of any user.
Recommendations
For Nextcloud Social app version 0.3.1, update to a version that fixes the improper access control issue.
Exploit
Fix
Incorrect Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Social App