CVE Published: 05/07/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: hackerone |
Vendor: Nextcloud |
Product: Nextcloud Server Status : PUBLISHED
CVE-2018-3762 Description
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.