Improper access control in Nextcloud Server and Nextcloud Enterprise Server - CVE-2023-25161
Published: February 22, 2023
Nextcloud Server
Nextcloud Enterprise Server
Nextcloud
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the password reset functionality. A remote attacker can send lots of emails, leading to service slowdown, storage overflow and cost impact when using external email services.