VYPR
Medium severity4.6NVD Advisory· Published Jun 14, 2024· Updated Jun 17, 2026

CVE-2024-37316

CVE-2024-37316

Description

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.

Affected products

3
  • Range: >= 4.3.0, < 4.6.8
  • Nextcloud/Calendarllm-fuzzy2 versions
    before 4.6.8 and 4.7.2+ 1 more
    • (no CPE)range: before 4.6.8 and 4.7.2
    • cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*range: >=4.3.0,<4.6.8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.