CVE-2021-32733 Information
Description
Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13 20.0.11 and 21.0.3. The Nextcloud Text application shipped with Nextcloud server used a text/html Content-Type when serving files to users. Due the strict Content-Security-Policy shipped with Nextcloud this issue is not exploitable on modern browsers supporting Content-Security-Policy. The issue was fixed in versions 19.0.13 20.0.11 and 21.0.3. As a workaround use a browser that has support for Content-Security-Policy.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://hackerone.com/reports/1241460 https://github.com/nextcloud/text/pull/1689 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x4w3-jhcr-57pq
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: