CVE-2023-25150

MEDIUM

Nextcloud Richdocuments < 3.8.7 - Improper Access Control

Title source: rule
STIX 2.1

Description

Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the content of other users files. It is recommended that the Nextcloud Office App (Collabora Integration) is updated to 7.0.2 (Nextcloud 25), 6.3.2 (Nextcloud 24), 5.0.10 (Nextcloud 23), 4.2.9 (Nextcloud 21-22), or 3.8.7 (Nextcloud 15-20). There are no known workarounds for this issue.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_misc
https://github.com/nextcloud/richdocuments/pull/2669
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1788222

Scores

CVSS v3 5.8
EPSS 0.0019
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-732
Status published
Products (1)
nextcloud/richdocuments < 3.8.7
Published Feb 08, 2023
Tracked Since Feb 18, 2026