Medium severity4.9NVD Advisory· Published Feb 4, 2020· Updated Jun 17, 2026
CVE-2019-15624
CVE-2019-15624
Description
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- cpe:2.3:o:suse:suse_linux_enterprise_server:12:-:*:*:*:*:*:*
- Range: <=15.0.7
- osv-coords4 versionspkg:rpm/opensuse/nextcloud&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015%20SP1
< 15.0.14-bp151.3.3.1+ 3 more
- (no CPE)range: < 15.0.14-bp151.3.3.1
- (no CPE)range: < 15.0.14-bp151.3.3.1
- (no CPE)range: < 15.0.14-bp151.3.3.1
- (no CPE)range: < 15.0.14-bp151.3.3.1
Patches
Vulnerability mechanics
References
4- hackerone.com/reports/508493nvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.htmlnvdMailing ListThird Party Advisory
- nextcloud.com/security/advisory/nvdVendor Advisory
News mentions
0No linked articles in our index yet.