A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
- https://hackerone.com/reports/231917
No PoCs found on GitHub currently.