Description
The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.
INFO
Published Date :
2025-12-05T17:37:06.767Z
Last Modified :
2025-12-05T18:10:00.615Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-66515 vulnerability.
| Vendors | Products |
|---|---|
| Nextcloud |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-66515.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact