A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://hackerone.com/reports/812754 | third party advisory exploit |
https://nextcloud.com/security/advisory/?id=NC-SA-2021-003 | vendor advisory |