CVE-2025-66546: Nextcloud Calendar app allowed booking appointments without the generated token
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66546?
CVE-2025-66546 is classified as a medium severity vulnerability due to its potential for unauthorized appointment bookings.
How do I fix CVE-2025-66546?
To fix CVE-2025-66546, upgrade the Nextcloud Calendar app to version 4.7.19, 5.5.6, or 6.0.1.
What systems are affected by CVE-2025-66546?
CVE-2025-66546 affects Nextcloud Calendar app versions prior to 4.7.19, 5.5.6, and 6.0.1.
What type of vulnerability is CVE-2025-66546?
CVE-2025-66546 is a vulnerability that allows unauthorized appointment bookings due to sequential ID handling.
When was CVE-2025-66546 disclosed?
CVE-2025-66546 was disclosed prior to the releases that fixed the issue in version 4.7.19, 5.5.6, and 6.0.1.