PoC Index

CVE-2019-15623

MEDIUM 5.3EPSS 1.9%

Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.92% chance of exploitation in the next 30 days, 78th percentile
Published
2020-02-04
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related