XSS in image metadata field

Disclosed: 2020-08-05 07:04:46 By yzy9951 To nextcloud
Medium
Vulnerability Details
Hi, Will you confirm the XSS vulnerability blocked by the CSP? On Nextcloud 19.0.0 1. Upload the PoC.jpg 2. Check the PoC.jpg metadata 3. Need bypass the CSP to trigger it ## Impact Cross-Site Scripting
Actions
View on HackerOne
Report Stats
  • Report ID: 896511
  • State: Closed
  • Substate: resolved
  • Upvotes: 11
Share this report