Improper access control in Nextcloud Richdocuments - CVE-2023-25159
Published: February 22, 2023
Vulnerability identifier: #VU72489
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25159
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to previews are accessible without a watermark. A local administrator can bypass implemented security restrictions and gain unauthorized access to sensitive information on the system.
Affected software
Nextcloud Richdocuments
Nextcloud Server
Nextcloud Enterprise Server
Nextcloud Server
Nextcloud Enterprise Server
How to mitigate CVE-2023-25159
Install updates from vendor's website.
Nextcloud Richdocuments - addressed in versions 6.3.1, 7.0.1
Nextcloud Server - addressed in versions 24.0.8, 25.0.1
Nextcloud Enterprise Server - addressed in versions 24.0.8, 25.0.1
Nextcloud Server - addressed in versions 24.0.8, 25.0.1
Nextcloud Enterprise Server - addressed in versions 24.0.8, 25.0.1