CVE-2018-3776

MEDIUM

Nextcloud Server < 11.0.5 - Log Information Exposure

Title source: rule
STIX 2.1

Description

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://hackerone.com/reports/232347

Scores

CVSS v3 5.3
EPSS 0.0027
EPSS Percentile 50.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-532 CWE-20
Status published
Products (1)
nextcloud/nextcloud_server 11.0.0 - 11.0.5
Published Aug 12, 2018
Tracked Since Feb 18, 2026