Description
Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.
Published: 2024-06-14
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-36574 Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.
History

Mon, 19 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud calendar
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*
Vendors & Products Nextcloud
Nextcloud calendar

Subscriptions

Nextcloud Calendar
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T03:50:56.106Z

Reserved: 2024-06-05T20:10:46.498Z

Link: CVE-2024-37316

cve-icon Vulnrichment

Updated: 2024-07-12T19:04:03.246Z

cve-icon NVD

Status : Modified

Published: 2024-06-14T16:15:11.707

Modified: 2024-11-21T09:23:35.837

Link: CVE-2024-37316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses