← Back

CVE-2025-66554

nvd nist
Published: Dec 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.

Affected (3)

Products: Nextcloud: Contacts
1 product
Contacts
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 5.0.0 to 5.5.4
From 6.0.0 to 6.0.6
From 7.0.0 to 7.2.5

References (4)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
Permissions RequiredVendor Advisory

Timeline

No history available yet.