VYPR

Social

by Nextcloud

CVEs (2)

  • CVE-2020-8279HigNov 19, 2020
    risk 0.48cvss 7.4epss 0.01

    Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.

  • CVE-2020-8278MedNov 19, 2020
    risk 0.35cvss 5.3epss 0.01

    Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.