CVE-2023-25817

LOW

Nextcloud Server < 24.0.9 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This issue has been addressed andit is recommended that the Nextcloud Server is upgraded to 24.0.9. There are no known workarounds for this vulnerability.

Scores

CVSS v3 3.5
EPSS 0.0016
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-281 CWE-732
Status published
Products (1)
nextcloud/nextcloud_server 24.0.0 - 24.0.9
Published Mar 27, 2023
Tracked Since Feb 18, 2026