CVE-2020-8235

4.3MEDIUM

Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

Published: 10/5/2020Updated: 11/21/2024

Description

Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

AI AnalysisPowered by AI

Affected Products

nextclouddeck
1.0.4

References