VYPR
High severity8.3NVD Advisory· Published Aug 4, 2022· Updated Jun 17, 2026

CVE-2022-31132

CVE-2022-31132

Description

Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS minifier on the path ./vendor/cerdic/css-tidy/css_optimiser.php. Access to the minifier is unrestricted and access may lead to Server-Side Request Forgery (SSRF). It is recommendet to upgrade to Mail 1.12.7 or Mail 1.13.6. Users unable to upgrade may manually delete the file located at ./vendor/cerdic/css-tidy/css_optimiser.php

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nextcloud/Mail2 versions
    cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*range: <1.12.8
    • (no CPE)range: before 1.12.7 or 1.13.6
  • Range: < 1.12.8

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.