CVE-2018-16463

A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.1 LOW
NETWORK
HIGH
HIGH
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
hackeroneCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
nextcloudnextcloud_server
𝑥
< 12.0.8
nextcloudnextcloud_server
13.0.0 ≤
𝑥
< 13.0.3
nextcloudnextcloud_server
14.0.0:beta1
nextcloudnextcloud_server
14.0.0:beta2
nextcloudnextcloud_server
14.0.0:beta3
nextcloudnextcloud_server
14.0.0:beta4
nextcloudnextcloud_server
14.0.0:rc1
nextcloudnextcloud_server
14.0.0:rc2
𝑥
= Vulnerable software versions