CVE-2024-52515

CVSS 3.1 Score 5.7 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 706

Summary

CVE-2024-52515 is a vulnerability affecting Nextcloud Server, a self-hosted personal cloud system. When an administrator enables the SVG preview provider, a malicious user can upload manipulated SVG files that reference external paths. If the referenced file exists, the SVG preview will display it instead, leading to potential data exposure. To mitigate this issue, it is recommended that Nextcloud Server versions 27.1.10, 28.0.6, and 29.0.1, as well as Nextcloud Enterprise Server versions 24.0.12.15, 25.0.13.10, 26.0.13.4, 27.1.10, 28.0.6, and 29.0.1, be upgraded.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nextcloud Server

Affected Vendors

  • Nextcloud GmbH