Nextcloud talk is a self hosting... CVE-2021-41180

4.0 AV AC AU C I A
发布: 2022-03-08
修订: 2024-11-21

Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user interaction. This only affected users of the Android Talk client. It is recommended that the Nextcloud Talk App is upgraded to 12.1.2. There are no known workarounds.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息