CVE-2025-66511: Nextcloud Calendar app used predictable proposal participant tokens
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated. This vulnerability is fixed in 6.0.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66511?
CVE-2025-66511 is categorized as a moderate severity vulnerability due to the potential for unauthorized access to meeting details.
How do I fix CVE-2025-66511?
To fix CVE-2025-66511, upgrade the Nextcloud Calendar app to version 6.0.3 or later.
What versions are affected by CVE-2025-66511?
CVE-2025-66511 affects Nextcloud Calendar versions prior to 6.0.3.
What type of vulnerability is CVE-2025-66511?
CVE-2025-66511 is a cryptographic vulnerability that allows for the computation of valid participant tokens.
What are the potential impacts of CVE-2025-66511?
The potential impacts of CVE-2025-66511 include unauthorized manipulation of meeting proposals and access to sensitive scheduling information.