PoC Index

CVE-2016-7419

MEDIUM 5.4EPSS 1.4%

Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.

CVSS v3.0
5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
1.37% chance of exploitation in the next 30 days, 70th percentile
Published
2016-09-17
Updated
2024-08-06

Proof-of-concept exploits (1)

References

Related