4.9
CVSSv2

CVE-2017-0936

Published: 28/03/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.7 | Impact Score: 3.6 | Exploitability Score: 2.1
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P

Vulnerability Summary

Nextcloud Server prior to 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.

Vulnerable Product Search on Vulmon Subscribe to Product

nextcloud nextcloud server

nextcloud nextcloud server 12.0.5