CVE-2019-5450

MEDIUM

Nextcloud Android App < 3.7.0 - Stored Cross-Site Scripting via Directory Name HTML Injection

Title source: llm
STIX 2.1

Description

Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/631227

Scores

CVSS v3 6.8
EPSS 0.0014
EPSS Percentile 33.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-80 CWE-79
Status published
Products (1)
nextcloud/nextcloud < 3.7.0
Published Jul 30, 2019
Tracked Since Feb 18, 2026