Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud in Nextcloud’s PDF viewer with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367. | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis. |
Thu, 04 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud in Nextcloud’s PDF viewer with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367. | |
| First Time appeared |
Nextcloud
Nextcloud nextcloud |
|
| Weaknesses | CWE-749 | |
| CPEs | cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nextcloud
Nextcloud nextcloud |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-04T00:00:00.000Z
Updated: 2025-12-04T19:02:03.447Z
Reserved: 2025-09-19T00:00:00.000Z
Link: CVE-2025-59788
No data.
Status : Received
Published: 2025-12-04T19:16:04.380
Modified: 2025-12-04T19:16:04.380
Link: CVE-2025-59788
No data.
ReportizFlow