Description

The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.

INFO

Published Date :

2025-12-05T17:37:06.767Z

Last Modified :

2025-12-05T18:10:00.615Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-66515 vulnerability.

Vendors Products
Nextcloud
  • Approval

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact