PT-2020-9746 · Nextcloud · Nextcloud Android App

Published

2020-02-04

·

Updated

2020-02-12

·

CVE-2019-15622

CVSS v3.1

2.4

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Android app version 3.6.0
Description The issue is related to insufficient sanitization in the Nextcloud Android app, allowing an attacker to obtain content information from protected tables when custom queries are used.
Recommendations For Nextcloud Android app version 3.6.0, update to a newer version that addresses the sanitization issue to prevent attackers from accessing protected table content.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15622

Affected Products

Nextcloud Android App