Description
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
References (2)
Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/851807
Vendor Advisory x_refsource_misc
https://nextcloud.com/security/advisory/?id=NC-SA-2020-021
Scores
CVSS v3
9.9
EPSS
0.0072
EPSS Percentile
72.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
nextcloud/talk
< 6.0.5
Published
Jun 08, 2020
Tracked Since
Feb 18, 2026