VYPR
Critical severity9.0NVD Advisory· Published Jun 5, 2019· Updated Jun 17, 2026

CVE-2019-12739

CVE-2019-12739

Description

lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).

Affected products

4
  • Nextcloud/Extract2 versions
    cpe:2.3:a:nextcloud:extract:*:*:*:*:*:nextcloud:*:*+ 1 more
    • cpe:2.3:a:nextcloud:extract:*:*:*:*:*:nextcloud:*:*range: <1.2.0
    • (no CPE)range: <1.2.0
  • Nextcloud/Extractdescription
  • Range: <1.2.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.