Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:* |
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud group Folders |
|
| Vendors & Products |
Nextcloud
Nextcloud group Folders |
Mon, 08 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2. | |
| Title | Nextcloud Groupfolders users with read-only permissions for team folder can restore deleted files from trash bin | |
| Weaknesses | CWE-707 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-05T17:44:13.312Z
Updated: 2025-12-08T19:55:13.290Z
Reserved: 2025-12-04T15:52:26.549Z
Link: CVE-2025-66545
Updated: 2025-12-08T19:55:10.517Z
Status : Analyzed
Published: 2025-12-05T18:15:57.803
Modified: 2025-12-09T19:10:33.430
Link: CVE-2025-66545
No data.