4.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Description
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.
Basic Information
ID
CVE-2025-66510
Source
GitHub_M
Published
Dec 5, 2025 at 16:18
Modified
Dec 5, 2025 at 20:02
Affected Product
Vendor
nextcloud
Product
security-advisories
Version
>= 32.0.0beta1, < 32.0.1
Affected Versions
nextcloud security-advisories >= 32.0.0beta1, < 32.0.1
nextcloud security-advisories < 31.0.10
nextcloud security-advisories < 31.0.10