HTML Injection in Directory Names in Nextcloud Android App (Versions < 3.7.0)

HTML Injection in Directory Names in Nextcloud Android App (Versions < 3.7.0)

CVE-2019-5450 · MEDIUM Severity

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.

Learn more about our Cis Benchmark Audit For Google Android.