Improper access control in Nextcloud Enterprise Server and Nextcloud Server - CVE-2023-25161
Published: February 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the password reset functionality. A remote attacker can send lots of emails, leading to service slowdown, storage overflow and cost impact when using external email services.
Affected software
Nextcloud Server
How to mitigate CVE-2023-25161
Nextcloud Server - addressed in versions 23.0.12, 24.0.8, 25.0.1