A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
- https://hackerone.com/reports/661051
No PoCs found on GitHub currently.