← volver
CVE-2023-33183

Error in calendar when booking an appointment reveals the full path of the website

CVSS 2.6 LOWEPSS 0.4%CWE-285
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 2.6EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
30 may 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →