VYPR
Medium severity4.1NVD Advisory· Published Jun 23, 2023· Updated Jun 17, 2026

CVE-2023-35171

CVE-2023-35171

Description

NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. Starting in version 26.0.0 and prior to version 26.0.2, an attacker could supply a URL that redirects an unsuspecting victim from a legitimate domain to an attacker's site. Nextcloud Server and Nextcloud Enterprise Server 26.0.2 contain a patch for this issue. No known workarounds are available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Nextcloud/Server3 versions
    cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*+ 2 more
    • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*range: >=26.0.0,<26.0.2
    • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*range: >=26.0.0,<26.0.2
    • (no CPE)range: 26.0.0 <= version < 26.0.2
  • Range: 26.0.0 <= version < 26.0.2
  • Range: >= 26.0.0, < 26.0.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.