CVE-2024-52511

MEDIUM

Nextcloud Tables < 0.8.0 - IDOR

Title source: rule
STIX 2.1

Description

Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.

Scores

CVSS v3 6.3
EPSS 0.0020
EPSS Percentile 41.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
nextcloud/tables 0.6.0 - 0.8.0
Published Nov 15, 2024
Tracked Since Feb 18, 2026