Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
- https://hackerone.com/reports/518669
No PoCs found on GitHub currently.