Description
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud server. Due to an endpoint where an attacker could influence the error message, this led to a reflected Cross-Site-Scripting vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin DukaPress SQL Injection (2.5.9)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2017-9120)
Apache Tomcat Improper Handling of Exceptional Conditions Vulnerability (CVE-2021-30639)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32731)
WordPress Plugin Advanced File Manager Information Disclosure (5.2.4)