VulnerabilityAnalyzed
CVE-2025-66554
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing.
MEDIUM 5.4EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- nextcloud/contacts
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/contacts/commit/d954d098978dde1f121600e8b994e02f293c68b1Patch
- https://github.com/nextcloud/contacts/pull/4619Issue Tracking, Patch
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v78-cpfc-v6h2Patch, Vendor Advisory
- https://hackerone.com/reports/3293290Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.