Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1. | |
| Title | Nextcloud Calendar app allowed booking appointments without the generated token | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-05T16:49:46.553Z
Updated: 2025-12-05T18:32:44.271Z
Reserved: 2025-12-04T15:52:26.549Z
Link: CVE-2025-66546
Updated: 2025-12-05T18:32:34.528Z
Status : Received
Published: 2025-12-05T17:16:05.163
Modified: 2025-12-05T17:16:05.163
Link: CVE-2025-66546
No data.