← Back

CVE-2023-33182

nvd nist
Published: May 30, 2023Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to be exploitable. It is recommended that the Contacts app is upgraded to 5.0.3 or 4.2.4

Affected (2)

Products: Nextcloud: Contacts
1 product
Contacts
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 4.1.0 to 4.2.4
From 5.0.0 to 5.0.3

References (6)

Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.