Delete All Data of Any User
Low
Vulnerability Details
If you are user have permission manage user(admin group), you can delete all data off website.
step:
1. Create new user with username is '.'.
2. Delete user, who just have been created.
Cause:
when you create new use, nextcloud app will make a new folder same name with username, which have been created. in folder (sourceweb/data)
Unfortunately, if username is '.', nextcloud app will make a new folder has name is '.'.
And when you delete user, nextcloud app will remote all folder 'data'.
Actions
View on HackerOneReport Stats
- Report ID: 220385
- State: Closed
- Substate: resolved
- Upvotes: 8