← back
CVE-2018-3780

CVE-2018-3780

EPSS 0.8%CWE-79
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Aug 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →