{"id":"CVE-2018-3763","details":"In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.","modified":"2026-07-08T20:04:08.287914Z","published":"2018-07-05T16:29:00.517Z","references":[{"type":"ADVISORY","url":"https://nextcloud.com/security/advisory/?id=nc-sa-2018-004"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/calendar","events":[{"introduced":"0"},{"fixed":"121ce5f3de37675300c8de73875017e2e76c388b"},{"introduced":"55c29b3fbe74e89597d8d4f3b794d3f2cde51e18"},{"last_affected":"55c29b3fbe74e89597d8d4f3b794d3f2cde51e18"}],"database_specific":{"cpe":["cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*","cpe:2.3:a:nextcloud:calendar:1.6.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"1.5.8"},{"introduced":"1.6.0"},{"last_affected":"1.6.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["1.6.0","v1.6.0","v1.5.6","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5.0","v1.4.1","v1.4.0","v1.3.3","v1.3.2","v1.3.1","v1.3.0","v1.2.2","v1.2.1","v1.2","v1.1","v1.0","v1.0-alpha2","v1.0-alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-3763.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}