Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 05 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts. | |
| Title | Nextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact list | |
| Weaknesses | CWE-359 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-05T20:02:53.678Z
Reserved: 2025-12-03T15:12:22.978Z
Link: CVE-2025-66510
Updated: 2025-12-05T20:02:45.644Z
Status : Received
Published: 2025-12-05T17:16:04.613
Modified: 2025-12-05T17:16:04.613
Link: CVE-2025-66510
No data.
OpenCVE Enrichment
No data.