CVE-2020-8179
02.07.2020, 19:15
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | deck | 𝑥 < 1.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.