VYPR
Low severity2.6NVD Advisory· Published Nov 15, 2024· Updated Jun 17, 2026

CVE-2024-52513

CVE-2024-52513

Description

Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8 or 30.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Nextcloud/Server2 versions
    cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*range: >=28.0.0,<28.0.11
    • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*range: >=25.0.0,<25.0.13.13
  • Range: up to 28.0.11, 29.0.8 or 30.0.1
  • Range: >= 28.0.0, < 28.0.11

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.