Vulnerabilities
Vulnerable Software
Nextcloud:  >> Mail  >> 3.1.1  Security Vulnerabilities
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotected endpoint in the Mail app to perform a SSRF attack. Nextcloud Mail app versions 2.2.8 and 3.3.0 contain a patch for this issue. As a workaround, disable the mail app.
CVSS Score
3.5
EPSS Score
0.002
Published
2023-11-21
Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, target and cookies allows for an attacker to abuse the proxy endpoint to denial of service a third server. It is recommended that the Nextcloud Mail is upgraded to 2.2.8 or 3.3.0. There are no known workarounds for this vulnerability.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-10-16


Contact Us

Shodan ® - All rights reserved