CVE-2023-39961

Published
View on NVD ↗
CVSS v3
3.5
LOW
CVSS v2
N/A
Affected
2
PROJECTS

Description

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prior to versions 25.0.9, 26.0.4, and 27.0.1, when a folder with images or an image was shared without download permissions, the user could add the image inline into a text file and download it. Nextcloud Server versions 25.0.9, 26.0.4, and 27.0.1 and Nextcloud Enterprise Server versions 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1 contain a patch for this issue. No known workarounds are available.

👮 Security advisories of Nextcloud
GitHubGitHub
75
📑 Collaborative document editing using Markdown
GitHubGitHub
640