Cross-Site Scripting Vulnerability in Nextcloud Desktop Client 2.6.4

Cross-Site Scripting Vulnerability in Nextcloud Desktop Client 2.6.4

CVE-2020-8189 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.

Learn more about our Cis Benchmark Audit For Desktop Software.