A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
nextcloud nextcloud server |