CVE-2024-52515
Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provider, a malicious user could upload a manipulated SVG file referencing paths. If the file would exist the preview of the SVG would preview the other file instead. It is recommended that the Nextcloud Server is upgraded to 27.1.10, 28.0.6 or 29.0.1 and Nextcloud Enterprise Server is upgraded to 24.0.12.15, 25.0.13.10, 26.0.13.4, 27.1.10, 28.0.6 or 29.0.1.
- Affected products
- Nextcloud Enterprise Server, Nextcloud Server, Red Os
- Nextcloud Nextcloud Server
- < 24.0.12.15, 25.0.13.10, 26.0.13.4, 27.1.10, 28.0.6, 29.0.1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.7% (48th percentile)
- Weakness
- CWE-706
- NVD status
- Analyzed
- Published
- 2024-11-15
CVE-2024-52515 at NVD
No indexed exploits for CVE-2024-52515 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-52515 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.