4.9

CVE-2019-15624

Exploit

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

Data is provided by the National Vulnerability Database (NVD)
NextcloudNextcloud Server Version < 14.0.11
NextcloudNextcloud Server Version >= 15.0.0 < 15.0.8
OpensuseBackports Versionsle-15 Updatesp1
SuseSuse Linux Enterprise Server Version12 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.32% 0.541
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.