CVE-2023-33182

NONE

Nextcloud Contacts 4.1.0-4.2.3 - Improper Input Validation in SVG Avatar Rendering

Title source: llm
STIX 2.1

Description

Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to be exploitable. It is recommended that the Contacts app is upgraded to 5.0.3 or 4.2.4

References (3)

Core 3
Core References
Permissions Required x_refsource_misc
https://hackerone.com/reports/1789602

Scores

CVSS v3 0.0
EPSS 0.0019
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
nextcloud/contacts 4.1.0 - 4.2.4
Published May 30, 2023
Tracked Since Feb 18, 2026