CVE-2020-8278
19.11.2020, 01:15
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | social | 0.3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.