Nextcloud has been updated to 13.0.6 and fixes atleast the following
security issue:
A missing sanitization of search results for an autocomplete field could
lead to a stored XSS requiring user-interaction. The missing sanitization
only affected user names, hence malicious search results could only be
crafted by authenticated users (CVE-2018-3780).
- https://bugs.mageia.org/show_bug.cgi?id=23497
- https://nextcloud.com/changelog/#latest13
- - - https://www.cve.org/CVERecord?id=CVE-2018-3780
- 6/core/nextcloud-13.0.6-1.mga6
Get the latest Linux and open source security news straight to your inbox.