PT-2024-27473 · Nextcloud · Nextcloud Calendar

Wwwshellcodeit

·

Published

2024-06-14

·

Updated

2024-08-19

·

CVE-2024-37316

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Calendar versions prior to 4.6.8 Nextcloud Calendar versions prior to 4.7.2
Description The issue allows authenticated users to create an event with manipulated attachment data, leading to a bad redirect for participants when clicked.
Recommendations For versions prior to 4.6.8, upgrade to version 4.6.8. For versions prior to 4.7.2, upgrade to version 4.7.2.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-37316
GHSA-2R7Q-VFMV-79QF

Affected Products

Nextcloud Calendar