Impact
A stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.
Patches
It is recommended that the Mail app is upgraded to 5.5.3.
Workarounds
References
For more information
If you have any questions or comments about this advisory:
Impact
A stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.
Patches
It is recommended that the Mail app is upgraded to 5.5.3.
Workarounds
References
For more information
If you have any questions or comments about this advisory: