CVE-2019-15622
Description
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Insufficient input sanitization in Nextcloud Android app 3.6.0 allows an attacker to read protected table content via custom queries.
Vulnerability
The Nextcloud Android app version 3.6.0 did not properly sanitize user input when processing custom queries. The insufficient sanitization allowed an attacker to access content information from protected database tables that should not have been exposed through the query interface. This vulnerability affects Nextcloud Android app 3.6.0 as disclosed in the official advisory [1].
Exploitation
An attacker with the ability to supply custom queries to the Nextcloud Android app (e.g., through a malicious app with query injection capabilities or by modifying network requests) can craft queries that bypass the intended access controls. No authentication beyond normal app usage is required if the attacker can inject the custom query. The attacker does not need elevated privileges on the device itself.
Impact
Successful exploitation leads to unauthorized disclosure of information from protected database tables. This constitutes a confidentiality breach, as the attacker can retrieve content that is normally restricted. The impact is limited to information disclosure; the attacker does not gain code execution or write access.
Mitigation
The vulnerability is fixed in Nextcloud Android app version 3.6.1, which was released after the advisory [1]. Users should update to version 3.6.1 or later via the Google Play Store or other distribution channels. No workarounds are documented for this issue.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Nextcloud/Nextcloud Android appdescription
- Range: =3.6.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/518669mitrex_refsource_MISC
- nextcloud.com/security/advisory/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.