CVE-2024-52507

LOW

Nextcloud Tables < 0.8.1 - IDOR

Title source: rule
STIX 2.1

Description

Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.

Scores

CVSS v3 3.5
EPSS 0.0017
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
nextcloud/tables 0.3.0 - 0.8.1
Published Nov 15, 2024
Tracked Since Feb 18, 2026