CVE-2018-16466 — Improper Access Control in Server
CWE-284 — Improper Access ControlCWE-273 — Improper Check for Dropped Privileges6 documents4 sources
Severity
8.1HIGHNVD
EPSS
0.1%
top 68.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 30
Latest updateMay 13
Description
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2