NA

CVE-2023-25820

Published: 22/03/2023 Updated: 29/03/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Enterprise Server is the enterprise version of the file server software. In Nextcloud Server versions 25.0.x before 25.0.5 and versions 24.0.x before 24.0.10 as well as Nextcloud Enterprise Server versions 25.0.x before 25.0.4, 24.0.x before 24.0.10, 23.0.x before 23.0.12.5, 22.x before 22.2.0.10, and 21.x before 21.0.9.10, when an attacker gets access to an already logged in user session they can then brute force the password on the confirmation endpoint. Nextcloud Server should upgraded to 24.0.10 or 25.0.4 and Nextcloud Enterprise Server should upgraded to 21.0.9.10, 22.2.10.10, 23.0.12.5, 24.0.10, or 25.0.4 to receive a patch. No known workarounds are available.

Vulnerable Product Search on Vulmon Subscribe to Product

nextcloud nextcloud server