LOW3.1
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
CVSS 2.0LOW 3.6
CVSS:2.0/AV:N/AC:H/Au:S/C:P/I:P/A:NCVSS 3.xLOW 3.1
CVSS:3.x/CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N