3.3

CVE-2025-66546

Nextcloud Calendar app allowed booking appointments without the generated token

Calendar app allowed booking appointments without the generated token

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
Mögliche Gegenmaßnahme
Calendar: * No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Calendar Version >= 4.0.0 < 4.7.19
Nextcloud ≫ Calendar Version >= 5.0.0 < 5.5.6
Nextcloud ≫ Calendar Version 6.0.0 Update -
Nextcloud ≫ Calendar Version 6.0.0 Update rc1
Nextcloud ≫ Calendar Version 6.0.0 Update rc2
Nextcloud ≫ Calendar Version 6.0.0 Update rc3
Nextcloud ≫ Calendar Version 6.0.0 Update rc4
Nextcloud ≫ Calendar Version 6.0.0 Update rc5
Nextcloud ≫ Calendar Version 6.0.0 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemNextcloud App
≫
Produkt Calendar
Version >= 4.0.0, < 4.7.19
Version >= 5.0.0, < 5.5.6
Version >= 6.0.0, < 6.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7x2j-2674-fj95
Patch
Vendor Advisory
https://github.com/nextcloud/calendar/pull/7537
Issue Tracking
https://github.com/nextcloud/calendar/commit/f41650c3681fc4a4130eb883f5c0899c011326b3
Patch
https://hackerone.com/reports/3275810
Vendor Advisory
Issue Tracking
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7x2j-2674-fj95
Third Party Advisory