CVE-2016-9465

EUVD-2016-10271
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. Due to not performing any kind of verification on the image content this is prone to a stored Cross-Site Scripting attack.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
nextcloudnextcloud_server
10.0.0 ≤
𝑥
< 10.0.1
owncloudowncloud
9.0.0 ≤
𝑥
< 9.0.6
owncloudowncloud
9.1.0 ≤
𝑥
< 9.1.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nextcloud
artful
dne
bionic
dne
cosmic
dne
precise
dne
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
owncloud
artful
dne
bionic
dne
cosmic
dne
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne