CVE-2023-33183 LOW

CVE-2023-33183: Error in calendar when booking an appointment reveals the full path of the website

Vendor Nextcloud
Product security-advisories
Weakness CWE-285
Published May 30, 2023
Last update January 10, 2025

CVSS base score

2.6/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3

Key dates

02Disclosure timeline

May 30, 2023 CVE published
January 10, 2025 Record updated