What the vulnerability does

01Description

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Key dates

02Disclosure timeline

May 8, 2017 CVE published
August 5, 2024 Record updated

Related vulnerabilities

04Related CVE