CVE-2022-39333Cross-site Scripting in Security-advisories

Severity
6.1MEDIUMNVD
CNA4.6
EPSS
0.4%
top 39.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25

Description

Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDnextcloud/desktop< 3.6.1

Patches

🔴Vulnerability Details

2
OSV
CVE-2022-39333: Nexcloud desktop is the Desktop sync client for Nextcloud2022-11-25
CVEList
Cross-site scripting (XSS) in Nextcloud Desktop Client2022-11-25

📋Vendor Advisories

1
Debian
CVE-2022-39333: nextcloud-desktop - Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can injec...2022
CVE-2022-39333 — Cross-site Scripting | cvebase