CVE-2016-7419

MEDIUM

Nextcloud Server < 9.0.52 and ownCloud Server < 9.0.4 - Authenticated Stored Cross-Site Scripting via Directory Name

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92373
Vendor Advisory x_refsource_confirm
https://owncloud.org/security/advisory/?id=oc-sa-2016-011
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/145355

Scores

CVSS v3 5.4
EPSS 0.0020
EPSS Percentile 41.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
nextcloud/nextcloud_server < 9.0.51
owncloud/owncloud < 9.0.3
Published Sep 17, 2016
Tracked Since Feb 18, 2026