← Retour aux CVEs
CVE-2016-9465
N/ADescription
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. Due to not performing any kind of verification on the image content this is prone to a stored Cross-Site Scripting attack.
Details CVE
Score CVSS v3.1N/A
Publie3/28/2017
Derniere modification4/20/2025
Sourcenvd
Observations honeypot0
Produits affectes
nextcloud:nextcloud_serverowncloud:owncloud
Faiblesses (CWE)
CWE-79CWE-79
References
https://github.com/nextcloud/server/commit/68ab8325c799d20c1fb7e98d670785176590e7d0(support@hackerone.com)
https://github.com/owncloud/core/commit/6bf3be3877d9d9fda9c66926fe273fe79cbaf58e(support@hackerone.com)
https://github.com/owncloud/core/commit/b5a5be24c418033cb2ef965a4f3f06b7b4213845(support@hackerone.com)
https://hackerone.com/reports/163338(support@hackerone.com)
https://nextcloud.com/security/advisory/?id=nc-sa-2016-008(support@hackerone.com)
https://owncloud.org/security/advisory/?id=oc-sa-2016-018(support@hackerone.com)
https://github.com/nextcloud/server/commit/68ab8325c799d20c1fb7e98d670785176590e7d0(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/owncloud/core/commit/6bf3be3877d9d9fda9c66926fe273fe79cbaf58e(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/owncloud/core/commit/b5a5be24c418033cb2ef965a4f3f06b7b4213845(af854a3a-2127-422b-91ae-364da2661108)
https://hackerone.com/reports/163338(af854a3a-2127-422b-91ae-364da2661108)
https://nextcloud.com/security/advisory/?id=nc-sa-2016-008(af854a3a-2127-422b-91ae-364da2661108)
https://owncloud.org/security/advisory/?id=oc-sa-2016-018(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.