PT-2023-30770 · Nextcloud · Nextcloud Calendar

Nvz0X

+1

·

Published

2023-12-21

·

Updated

2024-01-09

·

CVE-2023-48308

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Calendar app versions prior to 4.5.3
Description An issue exists where an attacker can gain access to the stacktrace and internal paths of the server when generating an exception while editing a calendar appointment.
Recommendations For versions prior to 4.5.3, upgrade the Nextcloud Calendar app to version 4.5.3 to resolve the issue. As a temporary workaround, consider restricting access to the calendar editing feature until the upgrade is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-48308
GHSA-FV3C-QVJR-5RV8

Affected Products

Nextcloud Calendar