Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-52513


Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8 or 30.0.1.


Published

2024-11-15T18:15:30.157

Last Modified

2025-10-01T18:04:28.290

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.6 (LOW)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud nextcloud_server < 25.0.13.13 Yes
Application nextcloud nextcloud_server < 26.0.13.9 Yes
Application nextcloud nextcloud_server < 27.1.11.9 Yes
Application nextcloud nextcloud_server < 28.0.11 Yes
Application nextcloud nextcloud_server < 28.0.11 Yes
Application nextcloud nextcloud_server < 29.0.8 Yes
Application nextcloud nextcloud_server < 29.0.8 Yes
Application nextcloud nextcloud_server < 30.0.1 Yes
Application nextcloud nextcloud_server < 30.0.1 Yes

References