Nextcloud Talk是德国Nextcloud公司的一款自托管的本地音频/视频和聊天通信服务。 Nextcloud Talk 14.1.0之前版本存在安全漏洞,该漏洞源于接收器不受broadcastPermission的保护,允许恶意应用程序监控通信。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 14.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39331 | 4.6 MEDIUM | Cross-site Scripting (XSS) in Nexcloud Desktop Client |
| CVE-2022-39332 | 4.6 MEDIUM | Cross-site scripting (XSS) in Nextcloud Desktop Client |
| CVE-2022-39333 | 4.6 MEDIUM | Cross-site scripting (XSS) in Nextcloud Desktop Client |
| CVE-2022-39339 | 4.3 MEDIUM | Cleartext Transmission of Sensitive Information in user_oidc |
| CVE-2022-39334 | 3.9 LOW | nextcloudcmd incorrectly trusts bad TLS certificates |
| CVE-2022-39338 | 3.5 LOW | Stored cross site scripting (XSS) vulnerability via Authorization Endpoint in user_oidc |
| CVE-2022-39346 | 3.5 LOW | Missing length validation of user displayname in nextcloud server |
No comments yet