Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.
The product does not handle or incorrectly handles when a particular element is not the expected type, e.g. it expects a digit (0-9) but is provided with a letter (A-Z).
Link | Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2r7q-vfmv-79qf | third party advisory |
https://github.com/nextcloud/calendar/pull/5966 | patch |
https://hackerone.com/reports/2457588 | issue tracking |