Unrated severityNVD Advisory· Published Feb 3, 2021· Updated Aug 4, 2024
CVE-2020-8294
CVE-2020-8294
Description
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
Affected products
1- Range: Fixed in 20.0.2, 19.0.5, 18.0.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/1023787mitrex_refsource_CONFIRM
- nextcloud.com/security/advisory/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.