A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5couldleadtoastoredXSSrequiringuser-interaction.Themissingsanitizationonlyaffectedusernames,hencemalicioussearchresultscouldonlybecraftedbyauthenticatedusers.