Vulnerabilities > Nextcloud > Talk > 3.2.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-02-04 | CVE-2019-15620 | Information Exposure vulnerability in Nextcloud Talk Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature. | 4.0 |
2020-02-04 | CVE-2019-15619 | Cross-site Scripting vulnerability in Nextcloud Deck and Nextcloud Server Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project. | 3.5 |
2018-08-13 | CVE-2018-3781 | Cross-site Scripting vulnerability in Nextcloud Talk A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. | 3.5 |