Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15622.json"