CVE-2024-22213

NONE
Published Jan 18, 2024 Modified Nov 21, 2024 CWE-79

Description

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability.

Is your site exposed to CVE-2024-22213?

Run a free security scan — no signup, results in seconds.

Weakness Type (CWE)

CWE-79 Cross-site Scripting (XSS)

Affected Products

Vendor Product
nextcloud deck
nextcloud deck

References

Frequently Asked Questions

What is CVE-2024-22213? +
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability.
What products are affected by CVE-2024-22213? +
CVE-2024-22213 affects products from nextcloud, specifically: deck. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-22213? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-22213 — free, no signup required.