What the vulnerability does

01Description

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

Key dates

02Disclosure timeline

May 8, 2017 CVE published
August 5, 2024 Record updated