CVE-2020-8189Cross-site Scripting in Desktop

CWE-79Cross-site Scripting10 documents6 sources
Severity
5.4MEDIUMNVD
EPSS
0.6%
top 29.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 21
Latest updateMay 24

Description

A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

NVDnextcloud/desktop< 2.6.5

🔴Vulnerability Details

3
GHSA
GHSA-vc58-g8xx-fx3p: A cross-site scripting error in Nextcloud Desktop client 22022-05-24
CVEList
CVE-2020-8189: A cross-site scripting error in Nextcloud Desktop client 22020-08-21
OSV
CVE-2020-8189: A cross-site scripting error in Nextcloud Desktop client 22020-08-21

📋Vendor Advisories

1
Debian
CVE-2020-8189: nextcloud-desktop - A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to presen...2020

💬Community

5
Bugzilla
CVE-2020-8189 nextcloud: XSS on the login attempt [epel-7]2020-08-24
Bugzilla
CVE-2020-8189 nextcloud-client: nextcloud: XSS on the login attempt [fedora-all]2020-08-24
Bugzilla
CVE-2020-8189 nextcloud: XSS on the login attempt2020-08-24
Bugzilla
CVE-2020-8189 nextcloud: XSS on the login attempt [fedora-all]2020-08-24
Bugzilla
CVE-2020-8189 nextcloud-client: nextcloud: XSS on the login attempt [epel-7]2020-08-24
CVE-2020-8189 — Cross-site Scripting in Desktop | cvebase