Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud nextcloud Nextcloud nextcloud Enterprise Server Nextcloud nextcloud Server Nextcloud server |
|
| Vendors & Products |
Nextcloud
Nextcloud nextcloud Nextcloud nextcloud Enterprise Server Nextcloud nextcloud Server Nextcloud server |
Fri, 05 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1. | |
| Title | Nextcloud Server users can modify tags on files that do not belong to them | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-05T16:32:17.359Z
Updated: 2025-12-05T18:20:43.503Z
Reserved: 2025-12-04T15:52:26.550Z
Link: CVE-2025-66547
Updated: 2025-12-05T18:20:33.143Z
Status : Received
Published: 2025-12-05T17:16:05.330
Modified: 2025-12-05T17:16:05.330
Link: CVE-2025-66547
No data.
ReportizFlow