CVE-2025-64011: Medium severity Nextcloud NextCloud Server vulnerability
Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64011?
CVE-2025-64011 is considered a high severity vulnerability due to its potential for unauthorized data access.
How do I fix CVE-2025-64011?
To fix CVE-2025-64011, update Nextcloud Server to the latest version that addresses this Insecure Direct Object Reference issue.
Who is affected by CVE-2025-64011?
Any authenticated user of Nextcloud Server 30.0.0 is affected by CVE-2025-64011 as they can access unauthorized file previews.
What type of vulnerability is CVE-2025-64011?
CVE-2025-64011 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
What impact does CVE-2025-64011 have on users?
CVE-2025-64011 allows unauthorized users to view sensitive files from other users, leading to potential data breaches.