Fedora Account System
Red Hat Associate
Red Hat Customer
Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud in Nextcloud’s PDF viewer with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367.