PT-2023-18524 · Nextcloud · Nextcloud Desktop Client

·

CVE-2023-22472

·

Published

2023-01-09

·

Updated

2023-01-13

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop client versions prior to 3.6.2
Description The issue affects Deck, a kanban style organization tool integrated with Nextcloud, allowing an attacker to make a user send any POST request with an arbitrary body if they click on a malicious deep link on a Windows computer. This could be done through various means such as email or chat links. There are no known workarounds for this issue.
Recommendations For versions prior to 3.6.2, upgrade the Nextcloud Desktop client to version 3.6.2 to resolve the issue. As a temporary workaround, consider avoiding the use of deep links from untrusted sources until the upgrade is applied.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-22472
GHSA-4GFV-XQPX-42QJ

Affected Products

Nextcloud Desktop Client