CVE-2017-0893

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
08/05/2017
Last modified:
20/04/2025

Description

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 9.0.58 (excluding)
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 10.0.0 (including) 10.0.5 (excluding)
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 11.0.0 (including) 11.0.3 (excluding)