Impact
The vulnerability resides in the Nextcloud Tables app where a missing sanitization allows a user with access to the app to inject malicious SQL code into the ORDER BY clause of a query. The injection is limited: it can extract one bit of information per request or induce a timed delay, rather than allowing full exploitation of the underlying database. Nonetheless, repeated exploitation could reveal sensitive data or be used for timing‑based attacks.
Affected Systems
Nextcloud Tables app versions 0.9.0 through 0.9.6 and 1.0.0 through 1.0.1 are affected. Versions 0.9.7 and later, and 1.0.2 and later contain the patch.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity, although the EPSS score is not available, indicating limited publicly known exploitation data. The flaw is not listed in the CISA KEV catalogue, and the attack likely requires the attacker to have legitimate or compromised credentials that grant access to the Tables app. The limited nature of the injection (single‑bit extraction or timing) means the immediate risk is moderate to high for organizations that expose the app to untrusted users, but mass exploitation is unlikely.
OpenCVE Enrichment