Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25160


Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail 1.12.9 for Nextcloud 21, or Mail 1.11.8 for Nextcloud 20 to receive a patch. No known workarounds are available.


Published

2023-02-13T21:15:14.673

Last Modified

2024-11-21T07:49:13.527

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-639
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud mail < 1.11.8 Yes
Application nextcloud mail < 1.12.9 Yes
Application nextcloud mail < 1.14.5 Yes
Application nextcloud mail < 2.2.1 Yes

References