CVE Database
/

CVE-2023-25820

Back to search

CVE-2023-25820

Published: Mar 22, 2023

Modified: Feb 25, 2025

PUBLISHED

CVSS v3.1

4.2

MEDIUM

Description

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Enterprise Server is the enterprise version of the file server software. In Nextcloud Server versions 25.0.x prior to 25.0.5 and versions 24.0.x prior to 24.0.10 as well as Nextcloud Enterprise Server versions 25.0.x prior to 25.0.4, 24.0.x prior to 24.0.10, 23.0.x prior to 23.0.12.5, 22.x prior to 22.2.0.10, and 21.x prior to 21.0.9.10, when an attacker gets access to an already logged in user session they can then brute force the password on the confirmation endpoint. Nextcloud Server should upgraded to 24.0.10 or 25.0.4 and Nextcloud Enterprise Server should upgraded to 21.0.9.10, 22.2.10.10, 23.0.12.5, 24.0.10, or 25.0.4 to receive a patch. No known workarounds are available.

VendorProductVersions

nextcloud

security-advisories

affected
Nextcloud Server >= 24.0.0, < 24.0.10
affected
Nextcloud Server >= 25.0.0, < 25.0.4
affected
Nextcloud Enterprise Server >= 25.0.0, < 25.0.4
affected
Nextcloud Enterprise Server >= 24.0.0, < 24.0.10
affected
Nextcloud Enterprise Server >= 23.0.0, < 23.0.12.5

+2 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Attack Vector

Local

Attack Complexity

High

Privileges Required

Low

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now