CVE-2018-3764

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
05/07/2018
Last modified:
04/03/2023

Description

In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nextcloud:contacts:*:*:*:*:*:*:*:* 2.1.2 (excluding)


References to Advisories, Solutions, and Tools