Nextcloud Talk是德国Nextcloud公司的一款自托管的本地音频/视频和聊天通信服务。 Nextcloud Talk 存在输入验证错误漏洞,该漏洞源于在 12.1.2 之前的版本中,由于缺乏对链接的验证,攻击者能够控制 Nextcloud Talk 应用程序中的地理位置预览链接。 这可能会导致打开重定向,但需要用户交互。 这仅影响 Android Talk 客户端的用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 12.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-41239 | 5.3 MEDIUM | User enumeration setting not respected in Nextcloud server |
| CVE-2021-41241 | 4.3 MEDIUM | Advanced permissions is not respected for subfolders in Nextcloud server |
| CVE-2021-41181 | 2.4 LOW | Nextcloud Talk app exposes chat messages on lockscreen |
No comments yet