← Back to CVE List

CVE-2017-0893

Published: 2017-05-08T20:29Z
Last Modified: 2024-11-21T03:03Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt