Share owner has no possibility to list all existing derived shares
N
Nextcloud
Submitted None
Actions:
Reported by
detroitsmash
Vulnerability Details
Technical details and impact analysis
Hi,
I found a bug where a shared link of particular file can disclose all files of that folder.
###Steps to reproduce
+ Make a group( ```http://*/nextcloud/index.php/settings/users```) and a standard user in it.
+ Now goto any folder and change it to gallery view
{F99993}
+ Invite that group which u made in step 1 with ``share`` privilege .
+ From standard user account, goto that shared folder and make a shared link of any file. E.g:
{F99992}
+ Untick the ``can share`` privilege from that group using folder owner account. Eg:
{F99994}
Now the shared link which was created by standard user will work as folder shared link. And when folder untick the ``can share`` privilege public is automatically created without asking folder owner.
Thanks
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic