What the vulnerability does

01Description

Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.

Key dates

02Disclosure timeline

February 4, 2020 CVE published
August 5, 2024 Record updated