CVE-2025-66511

MEDIUM

Nextcloud Calendar <6.0.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated. This vulnerability is fixed in 6.0.3.

Scores

CVSS v3 4.8
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-330
Status published
Products (1)
nextcloud/calendar 6.0.0 - 6.0.3
Published Dec 05, 2025
Tracked Since Feb 18, 2026