CVE-2024-52511

Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*

History

01 Oct 2025, 18:06

Type Values Removed Values Added
CPE cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*
First Time Nextcloud tables
Nextcloud
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4qqp-9h2g-7qg7 - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4qqp-9h2g-7qg7 - Vendor Advisory
References () https://github.com/nextcloud/tables/commit/52846ad81fe192ee977f14c82a229b0d9cdc406c - () https://github.com/nextcloud/tables/commit/52846ad81fe192ee977f14c82a229b0d9cdc406c - Patch
References () https://github.com/nextcloud/tables/pull/1351 - () https://github.com/nextcloud/tables/pull/1351 - Issue Tracking
References () https://hackerone.com/reports/2671404 - () https://hackerone.com/reports/2671404 - Issue Tracking

Information

Published : 2024-11-15 18:15

Updated : 2025-10-01 18:06


NVD link : CVE-2024-52511

Mitre link : CVE-2024-52511

CVE.ORG link : CVE-2024-52511


JSON object : View

Products Affected

nextcloud

  • tables
CWE
CWE-639

Authorization Bypass Through User-Controlled Key