CVE-2025-66510
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD
Description
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.
Affected (6)
Products: Nextcloud: Nextcloud Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 31.0.0 to 31.0.10 |
References (3)
Source: security-advisories@github.com
PatchVendor Advisory
Source: security-advisories@github.com
Patch
Timeline
No history available yet.