CVE-2024-52511
Nextcloud Tables has an Authorization Bypass Through User-Controlled Key in Tables
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
Affected products
nextcloud · security-advisoriesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →