PT-2025-21657 · Nextcloud+1 · Nextcloud Server+2

Nickvergessen

·

Published

2025-05-16

·

Updated

2025-09-19

·

CVE-2025-47791

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Nextcloud Server versions prior to 28.0.13 Nextcloud Server versions prior to 29.0.10 Nextcloud Server versions prior to 30.0.3 Nextcloud Enterprise Server versions prior to 28.0.13 Nextcloud Enterprise Server versions prior to 29.0.10 Nextcloud Enterprise Server versions prior to 30.0.3
Description: Nextcloud Server is a self-hosted personal cloud system. A currently unused endpoint to verify a share recipient was not protected correctly, allowing proxy requests to another server. No known workarounds are available.
Recommendations: For Nextcloud Server versions prior to 28.0.13, update to version 28.0.13 or later. For Nextcloud Server versions prior to 29.0.10, update to version 29.0.10 or later. For Nextcloud Server versions prior to 30.0.3, update to version 30.0.3 or later. For Nextcloud Enterprise Server versions prior to 28.0.13, update to version 28.0.13 or later. For Nextcloud Enterprise Server versions prior to 29.0.10, update to version 29.0.10 or later. For Nextcloud Enterprise Server versions prior to 30.0.3, update to version 30.0.3 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-07168
CVE-2025-47791
GHSA-C7VQ-M7F8-RX37

Affected Products

Nextcloud Enterprise Server
Nextcloud Server
Red Os