PT-2026-45536 · Nextcloud · Nextcloud
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Nextcloud versions 0.9.0 through 0.9.6
Nextcloud versions 1.0.0 through 1.0.1
Description
Missing sanitization in the Tables app allows a user with access to the application to perform a limited SQL injection within the ORDER BY statement of a query. This specific type of injection is restricted to extracting a single bit of information per request or inducing a time delay in the database response.
Recommendations
Update Nextcloud versions 0.9.0 through 0.9.6 to version 0.9.7.
Update Nextcloud versions 1.0.0 through 1.0.1 to version 1.0.2.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud