Skip to content

Huge security issue when sharing folder #9524

@SamuelBenard

Description

@SamuelBenard

The steps to share a folder and and a password are automatic and this could lead to big security issue if associated to browser's autofill feature.

Steps to reproduce

  1. Save your login credentials in your browser
  2. Login
  3. Create a folder
  4. Share it and enter an email (put you email as a test)
  5. You should receive an email saying that your cloud shared a folder with you
  6. On yout cloud page, In the email field, the email has been replaced by your login
  7. Click the 3 dots to "protect with a password"
  8. You receive an email with you login password

Expected behaviour

Shouldn't send password without confirmation, button or else

Actual behaviour

Sends the login password because of the autofill feature of the browser

Server configuration

Operating system:
Linux debian

Web server:
Apache 2

Database:
Mysql

PHP version:
7.2

Nextcloud version: (see Nextcloud admin page)
13.0.2

Metadata

Metadata

Assignees

No one assigned

    Labels

    0. Needs triagePending check for reproducibility or if it fits our roadmapbugsecurity

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions