Vulnerability advisory

CVE-2023-39955

Research by Md. Tareq Ahamed Jony August 10, 2023
Overview

Summary

Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.

Risk profile

CVSS assessment

3.5 · L O W
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack vector
N E T W O R K
Complexity
L O W
Privileges
L O W
User interaction
R E Q U I R E D
Scope
U N C H A N G E D
Confidentiality
N O N E
Integrity
L O W
Availability
N O N E
Classification

Weaknesses

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79
Configurations

Affected products

1 configuration
Vulnerable match
cpe:2.3:a:nextcloud:notes:*:*:*:*:*:nextcloud:*:*
From 4.4.0 inclusive Before 4.8.0
Further reading

References

3 sources
  1. github.com https://github.com/nextcloud/notes/pull/1031 Patch
  2. github.com https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6g88-37x7-4vw6 Patch Vendor Advisory
  3. hackerone.com https://hackerone.com/reports/1924355 Third Party Advisory