CVE Published: 03/02/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: hackerone |
Vendor: n/a |
Product: Nextcloud Server Status : PUBLISHED
CVE-2020-8294 Description
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a \'javascript:\' URL in markdown format.