VulnerabilityAnalyzed
CVE-2025-66553
Nextcloud Tables allows you to create your own tables with individual columns.
MEDIUM 4.3EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- nextcloud/tables
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6294-crjwPatch, Vendor Advisory
- https://github.com/nextcloud/tables/commit/e975f5bfedb6922f04cdd236cde4e26067fe064ePatch
- https://github.com/nextcloud/tables/pull/1891Issue Tracking
- https://hackerone.com/reports/3138721Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.