<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Nextcloud on Christian Niel Angel</title>
    <link>https://ctulhu.me/tags/nextcloud/</link>
    <description>Recent content in Nextcloud on Christian Niel Angel</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>© 2024 Christian Niel Angel</copyright>
    <lastBuildDate>Sun, 14 May 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://ctulhu.me/tags/nextcloud/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Full Passcode bypass on Nextcloud App iOS</title>
      <link>https://ctulhu.me/security/full-passcode-bypass-on-nextcloud-app-ios/</link>
      <pubDate>Sun, 14 May 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/full-passcode-bypass-on-nextcloud-app-ios/</guid>
      <description>It&amp;rsquo;s possible to fully access the user&amp;rsquo;s nextcloud files on Nextcloud App iOS by using the Files app on iPhone. Proof of Concept: # Download the nextcloud iOS app Login your account set a passcode Open the files app then go to &amp;gt; Browse Under the locations pick nextcloud click turn on References # https://hackerone.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/full-passcode-bypass-on-nextcloud-app-ios/featured.png" />
    </item>
    
    <item>
      <title>Ability to read any emails through IDOR on Nextcloud Mail</title>
      <link>https://ctulhu.me/security/ability-to-read-any-emails-through-idor-on-nextcloud-mail/</link>
      <pubDate>Fri, 12 May 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/ability-to-read-any-emails-through-idor-on-nextcloud-mail/</guid>
      <description> An attacker can access the mail box by ID getting the subjects and the first characters of the emails. References # https://hackerone.com/reports/1784681 https://nvd.nist.gov/vuln/detail/CVE-2023-25160 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m45f-r5gh-h6cx </description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/ability-to-read-any-emails-through-idor-on-nextcloud-mail/featured.png" />
    </item>
    
    <item>
      <title>Messages can still be seen on conversation after expiring when cron is misconfigured</title>
      <link>https://ctulhu.me/security/messages-can-still-be-seen-on-conversation-after-expiring-when-cron-is-misconfigured/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/messages-can-still-be-seen-on-conversation-after-expiring-when-cron-is-misconfigured/</guid>
      <description>Nextcloud talk has a feature called Message Expiration, Chat messages can be expired after a certain time. In order for messages to be removed from the database, the cron jobs need to be executed.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/messages-can-still-be-seen-on-conversation-after-expiring-when-cron-is-misconfigured/featured.png" />
    </item>
    
    <item>
      <title>Ability to control the filename when uploading a logo or favicon on theming</title>
      <link>https://ctulhu.me/security/ability-to-control-the-filename-when-uploading-a-logo-or-favicon-on-theming/</link>
      <pubDate>Mon, 10 Apr 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/ability-to-control-the-filename-when-uploading-a-logo-or-favicon-on-theming/</guid>
      <description>When uploading a logo or favicon the filename can be controlled by attacker since the key can be modified which serves as the filename. Proof of Concept: # go to http://localhost/settings/admin/theming upload a logo or favicon intercept the request using burp modify the key References # https://hackerone.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/ability-to-control-the-filename-when-uploading-a-logo-or-favicon-on-theming/featured.png" />
    </item>
    
    <item>
      <title>Passcode bypass on Talk Android app</title>
      <link>https://ctulhu.me/security/passcode-bypass-on-talk-android-app/</link>
      <pubDate>Thu, 05 Jan 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/passcode-bypass-on-talk-android-app/</guid>
      <description>It is possible to bypass the passcode protection in nextcloud android talk by clicking the notification of a message. Proof of Concept: # Create two users Using User A login it to the web interface while User B on Talk App Android Using User B setup the passcode protection in settings Using User A send a message to User B Wait for the notification and click it References # https://hackerone.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/passcode-bypass-on-talk-android-app/featured.png" />
    </item>
    
    <item>
      <title>File and Chat disclosure by calling the device while its in locked state</title>
      <link>https://ctulhu.me/security/file-and-chat-disclosure-by-calling-the-device-while-its-in-locked-state/</link>
      <pubDate>Wed, 09 Mar 2022 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/file-and-chat-disclosure-by-calling-the-device-while-its-in-locked-state/</guid>
      <description>Talk app allows access to sensitive chat messages on lockscreen during a call Summary # An attacker with physical access can gain access to the chat messages and files of the user by calling the victim phone while its in locked state.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/file-and-chat-disclosure-by-calling-the-device-while-its-in-locked-state/featured.png" />
    </item>
    
    <item>
      <title>Nextcloud Talk ObjectId in share location can be set to open arbitrary URL or Deeplinks</title>
      <link>https://ctulhu.me/security/nextcloud-talk-objectid-in-share-location-can-be-set-to-open-arbitrary-url-or-deeplinks/</link>
      <pubDate>Tue, 08 Mar 2022 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/nextcloud-talk-objectid-in-share-location-can-be-set-to-open-arbitrary-url-or-deeplinks/</guid>
      <description>It is possible to control the geolocation preview in the Nextcloud Talk app to point to a domain or deeplink which results to open-redirect. Summary # The nextcloud Talk app allows a User to share their location via app.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/nextcloud-talk-objectid-in-share-location-can-be-set-to-open-arbitrary-url-or-deeplinks/featured.png" />
    </item>
    
    <item>
      <title>CVE-2019-5450</title>
      <link>https://ctulhu.me/security/cve-2019-5450/</link>
      <pubDate>Mon, 15 Jul 2019 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/cve-2019-5450/</guid>
      <description>Some basic HTML tags were rendered as Markup in directory names. Product: Nextcloud App on Android Vendor : Nextcloud GmbH. Vulnerable Version: Nextcloud Android &amp;lt; 3.7.0 Category: Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) Vendor Notified: 2019-06-28 Patched: 2019-07-09 Researcher(s) : Christian Angel CVE: 2019-5450 Nextcloud is a suite of client-server software for creating and using file hosting services.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/cve-2019-5450/featured-nc.png" />
    </item>
    
  </channel>
</rss>
