← back
CVE-2024-37314

Nextcloud Photos' shared albums have no restriction on photo removal

CVSS 3.5 LOWEPSS 0.4%CWE-284
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.5EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
14 Jun 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →