CVE-2018-3776

MEDIUM

Nextcloud Server 11.0.0-11.0.5 - Audit Log Bypass via Input Validation Issue

Title source: llm
STIX 2.1

Description

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://hackerone.com/reports/232347

Scores

CVSS v3 5.3
EPSS 0.0126
EPSS Percentile 65.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-20 CWE-532
Status published
Products (1)
nextcloud/nextcloud_server 11.0.0 - 11.0.5
Published Aug 12, 2018
Tracked Since Feb 18, 2026