[Bug 1162779] New: VUL-1: CVE-2019-15618: nextcloud: Missing escaping of HTML in the Updater allowed a reflected XSS when starting the updater from a malicious location.