CVE-2022-39333

MEDIUM

Nextcloud Desktop < 3.6.1 - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.

Scores

CVSS v3 4.6
EPSS 0.0047
EPSS Percentile 64.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
nextcloud/desktop < 3.6.1
Published Nov 25, 2022
Tracked Since Feb 18, 2026