Sploitus

CVE-2023-25161

No indexed exploits for CVE-2023-25161 yet

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.

Nextcloud Nextcloud Server
< 23.0.12, 24.0.8, 25.0.0
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
0.7% (51th percentile)
Weakness
CWE-284
NVD status
Modified
Published
2023-02-13
CVE-2023-25161 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-25161 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-25161 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.