VYPR
Medium severity4.3NVD Advisory· Published Jul 10, 2020· Updated Jun 17, 2026

CVE-2020-8181

CVE-2020-8181

Description

A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:nextcloud:contacts:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nextcloud:contacts:*:*:*:*:*:*:*:*range: <3.3.0
    • (no CPE)range: =3.2.0
  • Nextcloud/Contactsdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.