CVE-2023-35928

CWE-2742 documents2 sources
Severity
8.8HIGH
EPSS
0.5%
top 36.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 23

Description

Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 19.0.0 until 19.0.13.9, 20.0.0 until 20.0.14.14, 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0 until 24.0.12.2, 25.0.0 until 25.0.7, and 26.0.0 until 26.0.2, a user could use this functionality to get access to the login credentials of another user and tak

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:HExploitability: 1.7 | Impact: 6.0

Affected Packages2 packages

NVDnextcloud/nextcloud_server19.0.019.0.13.9+7
CVEListV5nextcloud/security-advisories10 versions+9

🔴Vulnerability Details

1
CVEList
Nextcloud user scoped external storage can be used to gather credentials of other users2023-06-23
CVE-2023-35928 (HIGH CVSS 8.8) | Nextcloud Server is a space for dat | cvebase.io