Delete All Data of Any User

Disclosed: 2020-03-01 14:10:36 By dalt4sec To nextcloud
Low
Vulnerability Details
If you are user have permission manage user(admin group), you can delete all data off website. step: 1. Create new user with username is '.'. 2. Delete user, who just have been created. Cause: when you create new use, nextcloud app will make a new folder same name with username, which have been created. in folder (sourceweb/data) Unfortunately, if username is '.', nextcloud app will make a new folder has name is '.'. And when you delete user, nextcloud app will remote all folder 'data'.
Actions
View on HackerOne
Report Stats
  • Report ID: 220385
  • State: Closed
  • Substate: resolved
  • Upvotes: 8
Share this report