5.3

CVE-2023-25160

IDOR Vulnerability in Nextcloud Mail

IDOR Vulnerability in Nextcloud Mail

Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail 1.12.9 for Nextcloud 21, or Mail 1.11.8 for Nextcloud 20 to receive a patch. No known workarounds are available.
Mögliche Gegenmaßnahme
Mail: No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudMail Version < 1.11.8
NextcloudMail Version >= 1.12.0 < 1.12.9
NextcloudMail Version >= 1.13.0 < 1.14.5
NextcloudMail Version >= 2.0.0 < 2.2.1
Weitere Schwachstelleninformationen
SystemNextcloud App
Produkt Mail
Version >= 0.0.0, < 1.11.8
Version >= 1.12.0, < 1.12.9
Version >= 1.14.0, < 1.14.5
Version >= 2.2.0, < 2.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.561
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
security-advisories@github.com 4.1 2.3 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.