1 results (0.010 seconds)

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 2

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability. Deck es una herramienta de organización estilo kanban destinada a la planificación personal y organización de proyectos para equipos integrada con Nextcloud. • https://github.com/nextcloud/deck/commit/91f1557362047f8840f53151f176b80148650bcd https://github.com/nextcloud/security-advisories/security/advisories/GHSA-mg7w-x9fm-9wwc https://hackerone.com/reports/2058556 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •