Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
History

Fri, 15 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 17:30:00 +0000

Type Values Removed Values Added
Description Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
Title Nextcloud Tables has an Authorization Bypass Through User-Controlled Key in Tables
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-15T17:22:41.184Z

Updated: 2024-11-15T18:22:09.686Z

Reserved: 2024-11-11T18:49:23.558Z

Link: CVE-2024-52511

cve-icon Vulnrichment

Updated: 2024-11-15T18:22:03.696Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-15T18:15:29.717

Modified: 2024-11-18T17:11:56.587

Link: CVE-2024-52511

cve-icon Redhat

No data.