CVE-2025-47791
Last modified
CVE-2025-47791 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests to another server. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests to another server. The endpoint was removed in Nextcloud Server 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server 28.0.13, 29.0.10, and 30.0.3. No known workarounds are available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud Server | >= 28.0.0, < 28.0.13 |
| Nextcloud | Nextcloud Server | >= 29.0.0, < 29.0.10 |
| Nextcloud | Nextcloud Server | >= 30.0.0, < 30.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-47791?
How severe is CVE-2025-47791?
How do I fix CVE-2025-47791?
Are you affected by CVE-2025-47791?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
