PT-2021-22472 · Nextcloud · Nextcloud Contacts

Lukas Reschke

·

Published

2021-10-25

·

Updated

2021-10-27

·

CVE-2021-39221

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Contacts versions prior to 4.0.3
Description The Nextcloud Contacts application is vulnerable to a stored Cross-Site Scripting (XSS) issue. To exploit this, a user must right-click on a malicious file and open it in a new tab. However, due to the strict Content-Security-Policy in Nextcloud, this issue is not exploitable on modern browsers that support Content-Security-Policy.
Recommendations For versions prior to 4.0.3, upgrade the Nextcloud Contacts application to version 4.0.3. As a temporary workaround, consider using a browser that supports Content-Security-Policy to minimize the risk of exploitation.

Fix

Unrestricted File Upload

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39221
GHSA-J6CX-MXQF-F9VC

Affected Products

Nextcloud Contacts