Vulnerabilities > Nextcloud > Deck > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-10-05 CVE-2020-8235 Authorization Bypass Through User-Controlled Key vulnerability in Nextcloud Deck 1.0.4
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
network
low complexity
nextcloud CWE-639
4.0
2020-10-05 CVE-2020-8182 Improper Preservation of Permissions vulnerability in Nextcloud Deck 0.8.0
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
network
nextcloud CWE-281
6.0
2020-07-02 CVE-2020-8179 Improper Privilege Management vulnerability in Nextcloud Deck
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
network
low complexity
nextcloud CWE-269
4.0