CVE-2020-8154
12.05.2020, 13:15
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | nextcloud_server | 𝑥 < 17.0.5 |
nextcloud | nextcloud_server | 18.0.0 ≤ 𝑥 < 18.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References