CVE-2023-28833 LOW

CVE-2023-28833: Unrestricted filenames for logo or favicon as admin in the theming settings in nextcloud server

Vendor Nextcloud
Product security-advisories
Weakness CWE-22 · Path traversal
Published March 30, 2023
Last update February 11, 2025

CVSS base score

2.4/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to provided a file name which was not restricted and could overwrite files in the appdata directory. Administrators may have access to overwrite these files by other means but this method could be exploited by tricking an admin into uploading a maliciously named file. It is recommended that the Nextcloud Server is upgraded to 24.0.10 or 25.0.4. Users unable to upgrade should avoid ingesting logo files from untrusted sources.

Key dates

02Disclosure timeline

March 30, 2023 CVE published
February 11, 2025 Record updated