SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9467

An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

MEDIUM 5.3EPSS 2.97%

Does this matter?

Lower severity and a low EPSS score (2.97%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
2.97% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-451, CWE-284
Affected
nextcloud/nextcloud server · owncloud/owncloud
Source
support@hackerone.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.