CVE-2024-52515
CVSS 3.1 Score 5.7 of 10 (medium)
Details
Summary
CVE-2024-52515 is a vulnerability affecting Nextcloud Server, a self-hosted personal cloud system. When an administrator enables the SVG preview provider, a malicious user can upload manipulated SVG files that reference external paths. If the referenced file exists, the SVG preview will display it instead, leading to potential data exposure. To mitigate this issue, it is recommended that Nextcloud Server versions 27.1.10, 28.0.6, and 29.0.1, as well as Nextcloud Enterprise Server versions 24.0.12.15, 25.0.13.10, 26.0.13.4, 27.1.10, 28.0.6, and 29.0.1, be upgraded.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Nextcloud Server
Affected Vendors
- Nextcloud GmbH