3rd August 2018
Risk level: Medium
CVSS v3 Base Score: 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
HackerOne report: 232347
Improper validation of input allowed an attacker to not have their actions logged to the audit log.
The error has been fixed.
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory: