Bugzilla – Bug 1175662
VUL-0: CVE-2020-8189: nextcloud-desktop: cross-site scripting error allowed to present any html
Last modified: 2021-09-14 07:21:38 UTC
CVE-2020-8189 A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8189 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8189 https://hackerone.com/reports/685552 https://nextcloud.com/security/advisory/?id=NC-SA-2020-027
Hi Alexei, I'm not quite sure whether it is correct to assign it to you, please feel free to reassign it whenever necessary, thanks.
This is an old entry. We are now on 3.1.3. So it should fixed.