PT-2021-22472 · Nextcloud · Nextcloud Contacts
Lukas Reschke
·
Published
2021-10-25
·
Updated
2021-10-27
·
CVE-2021-39221
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Contacts versions prior to 4.0.3
Description
The Nextcloud Contacts application is vulnerable to a stored Cross-Site Scripting (XSS) issue. To exploit this, a user must right-click on a malicious file and open it in a new tab. However, due to the strict Content-Security-Policy in Nextcloud, this issue is not exploitable on modern browsers that support Content-Security-Policy.
Recommendations
For versions prior to 4.0.3, upgrade the Nextcloud Contacts application to version 4.0.3.
As a temporary workaround, consider using a browser that supports Content-Security-Policy to minimize the risk of exploitation.
Fix
Unrestricted File Upload
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Contacts