CVE-2019-15622

LOW

Nextcloud Android App < 3.6.1 - SQL Injection via Custom Queries

Title source: llm
STIX 2.1

Description

Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/518669

Scores

CVSS v3 2.4
EPSS 0.0013
EPSS Percentile 31.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
nextcloud/nextcloud < 3.6.1
Published Feb 04, 2020
Tracked Since Feb 18, 2026