Security Advisory

CVE-2020-8154

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-05-12 13:01:26
Last updated 2024-08-04 09:48:25
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.