Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud Server 21.0.8、22.2.4 和 23.0.1 之前版本存在数据伪造问题漏洞。攻击者利用该漏洞可以诱使管理员为他们不需要的 Nextcloud 服务器启用 recommended 应用程序,从而不必要地扩大其攻击面。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 21.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-24888 | 4.3 MEDIUM | Possible Injection in Nextcloud Server |
| CVE-2022-24887 | 4.3 MEDIUM | Open Redirect in Nextcloud Talk |
| CVE-2022-24886 | 2.2 LOW | Exposure of Sensitive Information to an Unauthorized Actor in com.nextcloud.client |
| CVE-2022-24885 | 2.0 LOW | Improper Authentication in Nextcloud Android Files |
No comments yet