Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://hackerone.com/reports/508493 | third party advisory exploit |
https://nextcloud.com/security/advisory/?id=NC-SA-2019-015 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.html | vendor advisory mailing list third party advisory |