Description


Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by the user.

Related CPE's


Weaknesses



CWE-200


CWE-200

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-06-11T14:15:11.597Z

4 years ago

Last modified

2024-11-21T04:50:53.157Z

1 year ago