CVE-2020-8180

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
08/06/2020
Last modified:
11/06/2020

Description

A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:* 6.0.5 (excluding)
cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.3 (excluding)
cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.8 (excluding)