Summary
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.
Risk profile
3.5 · L O W
CVSS assessment
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Attack vector
- N E T W O R K
- Complexity
- L O W
- Privileges
- L O W
- User interaction
- R E Q U I R E D
- Scope
- U N C H A N G E D
- Confidentiality
- N O N E
- Integrity
- L O W
- Availability
- N O N E
Weaknesses
-
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79
Configurations
1
configuration
Affected products
Vulnerable match
cpe:2.3:a:nextcloud:notes:*:*:*:*:*:nextcloud:*:*
From 4.4.0 inclusive
Before 4.8.0
Further reading
3
sources