4.9

CVE-2019-15624

Exploit
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Nextcloud Server Version < 14.0.11
Nextcloud ≫ Nextcloud Server Version >= 15.0.0 < 15.0.8
Opensuse ≫ Backports Version sle-15 Update sp1
Suse ≫ Suse Linux Enterprise Server Version 12 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.47% 0.704
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.html
Third Party Advisory
Mailing List
https://hackerone.com/reports/508493
Third Party Advisory
Exploit
https://nextcloud.com/security/advisory/?id=NC-SA-2019-015
Vendor Advisory