Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://hackerone.com/reports/490946 | third party advisory exploit |