Nextcloud Server before 11.0.3 is vulnerable to...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 20, 2025
Description
Published by the National Vulnerability Database
May 8, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Apr 20, 2025
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
References