Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 09 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:approval:*:*:*:*:*:nextcloud:*:* |
Fri, 05 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud approval |
|
| Vendors & Products |
Nextcloud
Nextcloud approval |
Fri, 05 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0. | |
| Title | Nextcloud Approval app allows users to request approval for other users file | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-05T18:10:00.615Z
Reserved: 2025-12-03T15:28:02.992Z
Link: CVE-2025-66515
Updated: 2025-12-05T18:09:54.033Z
Status : Analyzed
Published: 2025-12-05T18:15:57.623
Modified: 2025-12-09T17:22:18.077
Link: CVE-2025-66515
No data.
OpenCVE Enrichment
Updated: 2025-12-05T20:55:58Z