← volver
CVE-2022-39332

Cross-site scripting (XSS) in Nextcloud Desktop Client

CVSS 4.6 MEDIUMEPSS 0.9%CWE-79
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.6EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
25 nov 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application via user status and information. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →