Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hitman_47

#49364of 56,328
5.4Total CVSS
Vulnerabilities · 1
PT-2021-12717
5.4
2021-01-06
Nextcloud · Nextcloud Contacts · CVE-2020-8280
Name of the Vulnerable Software and Affected Versions: Nextcloud Contacts version 3.4.0 Description: A missing file type check allows a malicious user to upload SVG files as PNG files, enabling cross-site scripting (XSS) attacks. Recommendations: For Nextcloud Contacts version 3.4.0, consider restricting the upload of SVG files or implementing a proper file type check to prevent cross-site scripting attacks until a patch is available.