CVE-2016-7419
MEDIUMNextcloud Server < 9.0.52 and ownCloud Server < 9.0.4 - Authenticated Stored Cross-Site Scripting via Directory Name
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/92373
Vendor Advisory x_refsource_confirm
https://owncloud.org/security/advisory/?id=oc-sa-2016-011
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/145355
Patch x_refsource_confirm
https://github.com/nextcloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc
Vendor Advisory x_refsource_confirm
https://nextcloud.com/security/advisory/?id=nc-sa-2016-001
Scores
CVSS v3
5.4
EPSS
0.0020
EPSS Percentile
41.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
nextcloud/nextcloud_server
< 9.0.51
owncloud/owncloud
< 9.0.3
Published
Sep 17, 2016
Tracked Since
Feb 18, 2026