← Back

CVE-2025-47793

nvd nist
Published: May 16, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to 18.0.3, 17.0.5, and 16.0.11, the absence of quota checking on attachments allowed logged-in users to upload files exceeding the group folder quota. Nextcloud Server versions 30.0.2 and 29.0.9, Nextcloud Enterprise Server versions 30.0.2, 29.0.9, or 28.0.12, and Nextcloud Groupfolders app 18.0.3, 17.0.5, and 16.0.11 fix the issue. No known workarounds are available.

Affected (8)

2 products
Group Folders
Nextcloud Server
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 16.0.0 to 16.0.11
From 17.0.0 to 17.0.5
From 18.0.0 to 18.0.3
Nextcloud
From 29.0.0 to 29.0.9
From 30.0.0 to 30.0.2
From 28.0.0 to 28.0.12
From 29.0.0 to 29.0.9
From 30.0.0 to 30.0.2

References (4)

Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Permissions Required

Timeline

No history available yet.