Vulnerability Description
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud | <= 9.0.51 |
| Owncloud | Owncloud | <= 9.0.3 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/97282
- https://github.com/nextcloud/server/commit/2da43e3751576bbc838f238a09955c4dcdebeIssue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/server/commit/8aa0832bd449c44ec300da4189bd8ed4e0361Issue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/server/commit/dea8e29289a1b99d5e889627c2e377887f4f2Issue TrackingPatchThird Party Advisory
- https://github.com/owncloud/core/commit/c92c234059f8b1dc7d53122985ec0d398895a2cfIssue TrackingPatchThird Party Advisory
- https://hackerone.com/reports/145463ExploitThird Party Advisory
- https://nextcloud.com/security/advisory/?id=nc-sa-2016-003PatchVendor Advisory
- https://owncloud.org/security/advisory/?id=oc-sa-2016-013PatchVendor Advisory
- http://www.securityfocus.com/bid/97282
- https://github.com/nextcloud/server/commit/2da43e3751576bbc838f238a09955c4dcdebeIssue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/server/commit/8aa0832bd449c44ec300da4189bd8ed4e0361Issue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/server/commit/dea8e29289a1b99d5e889627c2e377887f4f2Issue TrackingPatchThird Party Advisory
- https://github.com/owncloud/core/commit/c92c234059f8b1dc7d53122985ec0d398895a2cfIssue TrackingPatchThird Party Advisory
- https://hackerone.com/reports/145463ExploitThird Party Advisory
- https://nextcloud.com/security/advisory/?id=nc-sa-2016-003PatchVendor Advisory
FAQ
What is CVE-2016-9460?
CVE-2016-9460 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. A...
How severe is CVE-2016-9460?
CVE-2016-9460 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-9460?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Nextcloud, Owncloud Owncloud.