CVE Vulnerabilities

CVE-2025-66545

Improper Neutralization

Published: Dec 05, 2025 | Modified: Dec 09, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.

Weakness

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Group_folders Nextcloud * 14.0.11 (excluding)
Group_folders Nextcloud 15.0.0 (including) 15.3.12 (excluding)
Group_folders Nextcloud 16.0.0 (including) 16.0.15 (excluding)
Group_folders Nextcloud 17.0.0 (including) 17.0.14 (excluding)
Group_folders Nextcloud 18.0.0 (including) 18.1.8 (excluding)
Group_folders Nextcloud 19.0.0 (including) 20.1.2 (excluding)

Extended Description

If a message is malformed, it may cause the message to be incorrectly interpreted. Neutralization is an abstract term for any technique that ensures that input (and output) conforms with expectations and is “safe.” This can be done by:

This weakness typically applies in cases where the product prepares a control message that another process must act on, such as a command or query, and malicious input that was intended as data, can enter the control plane instead. However, this weakness also applies to more general cases where there are not always control implications.

References