Description

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated. This vulnerability is fixed in 6.0.3.

INFO

Published Date :

2025-12-05T16:42:30.236Z

Last Modified :

2025-12-05T16:53:52.674Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-66511 vulnerability.

Vendors Products
Nextcloud
  • Calendar

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact