CVE-2021-41180

Published
View on NVD ↗
CVSS v3
4.7
MEDIUM
CVSS v2
4
MEDIUM
Affected
2
PROJECTS

Description

Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user interaction. This only affected users of the Android Talk client. It is recommended that the Nextcloud Talk App is upgraded to 12.1.2. There are no known workarounds.

🗨️ Nextcloud Talk – chat, video & audio calls for Nextcloud
GitHubGitHub
2.14K
👮 Security advisories of Nextcloud
GitHubGitHub
75