CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.8. See the original NVD description below for full technical details.
CVE
CVE-2018-3764
Severity
MEDIUM
CVSS
4.8
EPSS
0.64%
Original NVD Description
In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.
Related CVEs
Other vulnerabilities affecting the same vendor(s)