4.3

CVE-2025-66545

Nextcloud Groupfolders users with read-only permissions for team folder can restore deleted files from trash bin

Users with read-only permissions for team folder can restore deleted files from trash bin

Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.
Mögliche Gegenmaßnahme
Groupfolders: * Disable the Groupfolders app * Disable the Files_trashbin app
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudGroup Folders Version < 14.0.11
NextcloudGroup Folders Version >= 15.0.0 < 15.3.12
NextcloudGroup Folders Version >= 16.0.0 < 16.0.15
NextcloudGroup Folders Version >= 17.0.0 < 17.0.14
NextcloudGroup Folders Version >= 18.0.0 < 18.1.8
NextcloudGroup Folders Version >= 19.0.0 < 20.1.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemNextcloud App
Produkt Groupfolders
Version >= 0.0.0, < 14.0.11
Version >= 15.3.0, < 15.3.12
Version >= 16.0.0, < 16.0.15
Version >= 17.0.0, < 17.0.14
Version >= 18.1.0, < 18.1.8
Version >= 19.1.0, < 19.1.8
Version >= 20.1.0, < 20.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.062
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
security-advisories@github.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CWE-707 Improper Neutralization

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.