Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia: 2018-0394 Moderate: Nextcloud Security Update for XSS

mageia
Calendar Grey October 14, 2018
Dist Mageia Esm H88
Nextcloud has released version 13.0.6, which resolves a cross-site scripting vulnerability caused by inadequate sanitization in the autocomplete search inputs.
Nextcloud has been updated to 13.0.6 and fixes atleast the following security issue: A missing sanitization of search results for an autocomplete field could lead to a stored XSS ...

Summary

Nextcloud has been updated to 13.0.6 and fixes atleast the following security issue:
A missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users (CVE-2018-3780).

References

- https://bugs.mageia.org/show_bug.cgi?id=23497

- https://nextcloud.com/changelog/#latest13

- - - https://www.cve.org/CVERecord?id=CVE-2018-3780

Resolution

SRPMS

- 6/core/nextcloud-13.0.6-1.mga6

Publication date: 14 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0394.html
Type: security
CVE: CVE-2018-3780

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here