CVE-2025-66553
Last modified
CVE-2025-66553 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Tables | >= 0.8.0, < 0.8.7 |
| Nextcloud | Tables | >= 0.9.0, < 0.9.4 |
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6294-crjwPatch, Vendor Advisory
- https://github.com/nextcloud/tables/pull/1891Issue Tracking
- https://hackerone.com/reports/3138721Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66553?
How severe is CVE-2025-66553?
How do I fix CVE-2025-66553?
Are you affected by CVE-2025-66553?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
