// For flags

CVE-2016-9466

 

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud server. Due to an endpoint where an attacker could influence the error message, this led to a reflected Cross-Site-Scripting vulnerability.

Nextcloud Server en versiones anteriores a 10.0.1 y ownCloud Server en versiones anteriores a 9.0.6 y 9.1.2 sufren de Reflexed XSS en la aplicación Galería. La aplicación de la galería no estaba correctamente desinfectando los mensajes de excepción del servidor Nextcloud/ownCloud. Debido a un punto final en el que un atacante podría influir en el mensaje de error, esto llevó a una vulnerabilidad de secuencias de comandos en sitios cruzados reflejada.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-11-19 CVE Reserved
  • 2017-03-28 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nextcloud
Search vendor "Nextcloud"
Nextcloud Server
Search vendor "Nextcloud" for product "Nextcloud Server"
>= 10.0.0 < 10.0.1
Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 10.0.0 < 10.0.1"
-
Affected
Owncloud
Search vendor "Owncloud"
Owncloud
Search vendor "Owncloud" for product "Owncloud"
>= 9.0.0 < 9.0.6
Search vendor "Owncloud" for product "Owncloud" and version " >= 9.0.0 < 9.0.6"
-
Affected
Owncloud
Search vendor "Owncloud"
Owncloud
Search vendor "Owncloud" for product "Owncloud"
>= 9.1.0 < 9.1.2
Search vendor "Owncloud" for product "Owncloud" and version " >= 9.1.0 < 9.1.2"
-
Affected