Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
- https://hackerone.com/reports/916704
No PoCs found on GitHub currently.