4.3
CVSSv3

CVE-2019-5449

Published: 30/07/2019 Updated: 16/10/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nextcloud nextcloud server

Github Repositories

A local scanner for vulnerable web applications

freewvs A local web vulnerability scanner freewvs is a tool to search webroots for know vulnerable versions of web applications install Install You can install freewvs via pip: pip install freewvs Alternatively you can run freewvs directly from the git source If you install via pip you need to update the freewvs database first: update-