VYPR
Unrated severityNVD Advisory· Published Feb 4, 2020· Updated Aug 5, 2024

CVE-2019-15622

CVE-2019-15622

Description

Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Insufficient input sanitization in Nextcloud Android app 3.6.0 allows an attacker to read protected table content via custom queries.

Vulnerability

The Nextcloud Android app version 3.6.0 did not properly sanitize user input when processing custom queries. The insufficient sanitization allowed an attacker to access content information from protected database tables that should not have been exposed through the query interface. This vulnerability affects Nextcloud Android app 3.6.0 as disclosed in the official advisory [1].

Exploitation

An attacker with the ability to supply custom queries to the Nextcloud Android app (e.g., through a malicious app with query injection capabilities or by modifying network requests) can craft queries that bypass the intended access controls. No authentication beyond normal app usage is required if the attacker can inject the custom query. The attacker does not need elevated privileges on the device itself.

Impact

Successful exploitation leads to unauthorized disclosure of information from protected database tables. This constitutes a confidentiality breach, as the attacker can retrieve content that is normally restricted. The impact is limited to information disclosure; the attacker does not gain code execution or write access.

Mitigation

The vulnerability is fixed in Nextcloud Android app version 3.6.1, which was released after the advisory [1]. Users should update to version 3.6.1 or later via the Google Play Store or other distribution channels. No workarounds are documented for this issue.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.