5.4
CVE-2025-66554
- EPSS 0.02%
- Veröffentlicht 05.12.2025 17:50:59
- Zuletzt bearbeitet 09.12.2025 17:01:51
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field
Stored XSS in contacts app via organisation and title field
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.
Mögliche Gegenmaßnahme
Contacts: * Disable app Contacts
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemNextcloud App
≫
Produkt
Contacts
Version
>= 5.0.0, < 5.5.4
Version
>= 6.0.0, < 6.0.6
Version
>= 7.0.0, < 7.2.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.039 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| security-advisories@github.com | 3.5 | 2.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.