CVE-2024-37316
- EPSS 0.31%
- Veröffentlicht 14.06.2024 16:15:11
- Zuletzt bearbeitet 21.11.2024 09:23:35
Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4...
CVE-2023-48308
- EPSS 0.27%
- Veröffentlicht 22.12.2023 00:15:34
- Zuletzt bearbeitet 21.11.2024 08:31:27
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgrad...
CVE-2023-45150
- EPSS 0.12%
- Veröffentlicht 16.10.2023 20:15:15
- Zuletzt bearbeitet 21.11.2024 08:26:27
Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the ser...
CVE-2023-33183
- EPSS 0.18%
- Veröffentlicht 30.05.2023 06:16:35
- Zuletzt bearbeitet 21.11.2024 08:05:04
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3
CVE-2022-24838
- EPSS 8.78%
- Veröffentlicht 11.04.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:12
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can...
CVE-2018-3763
- EPSS 0.35%
- Veröffentlicht 05.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:01
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results...