PT-2022-16913 · Nextcloud+1 · Nextcloud Calendar+1

Miaulalala

+1

·

Published

2022-04-11

·

Updated

2025-03-26

·

CVE-2022-24838

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nextcloud Calendar versions prior to 3.2.2
Description The issue concerns SMTP Command Injection in appointment emails. It occurs because newlines and special characters in the email value within the JSON request are not sanitized. This allows a malicious attacker to inject newlines, breaking out of the RCPT TO:<BOOKING USER'S EMAIL> SMTP command and enabling the injection of arbitrary SMTP commands.
Recommendations For versions prior to 3.2.2, upgrade to version 3.2.2 to resolve the issue. At the moment, there are no workarounds available for this issue.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03807
CVE-2022-24838
GHSA-8XV5-4855-24QF

Affected Products

Nextcloud Calendar
Red Os