CVE-2024-37316: Nextcloud Calendar's event create can create attachments that link to other websites
Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37316?
CVE-2024-37316 has a moderate severity level due to its potential impact on authenticated users within Nextcloud Calendar.
How do I fix CVE-2024-37316?
To fix CVE-2024-37316, upgrade the Nextcloud Calendar App to version 4.6.8 or 4.7.2.
What are the risks of CVE-2024-37316?
The risks of CVE-2024-37316 include unauthorized redirecting of participants to malicious links through manipulated attachment data.
Who is affected by CVE-2024-37316?
Authenticated users of the Nextcloud Calendar app versions below 4.6.8 are affected by CVE-2024-37316.
Is Nextcloud Calendar version 4.3.0 vulnerable to CVE-2024-37316?
Yes, Nextcloud Calendar version 4.3.0 is vulnerable to CVE-2024-37316 and should be upgraded to mitigate the risk.