HTML injection in search UI when selecting a circle with HTML in the display name
Package
Server
(Nextcloud)
Affected versions
>= 25.0.0, >= 26.0.0, >= 27.0.0
Patched versions
25.0.13, 26.0.8, 27.1.3
Server
(Nextcloud Enterprise)
>= 25.0.0, >= 26.0.0, >= 27.0.0
25.0.13, 26.0.8, 27.1.3
Impact
An attacker could insert links into circles name that would be opened when clicking the circle name in a search filter.
Patches
It is recommended that the Nextcloud Server is upgraded to 25.0.13, 26.0.8 or 27.1.3
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.13, 26.0.8 or 27.1.3
Workarounds
References
For more information
If you have any questions or comments about this advisory: