PT-2023-18523 · Nextcloud · Nextcloud Deck

Nickvergessen

·

Published

2023-01-14

·

Updated

2023-01-24

·

CVE-2023-22471

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Deck app versions prior to 1.6.5 Nextcloud Deck app versions prior to 1.7.3 Nextcloud Deck app versions prior to 1.8.2
Description The issue is related to broken access control, allowing a user to delete attachments of other users. There are currently no known workarounds for this problem.
Recommendations For versions prior to 1.6.5, upgrade to version 1.6.5 or later. For versions prior to 1.7.3, upgrade to version 1.7.3 or later. For versions prior to 1.8.2, upgrade to version 1.8.2 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2023-22471
GHSA-2VW5-PFG6-3WM6

Affected Products

Nextcloud Deck