Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provider, a malicious user could upload a manipulated SVG file referencing paths. If the file would exist the preview of the SVG would preview the other file instead. It is recommended that the Nextcloud Server is upgraded to 27.1.10, 28.0.6 or 29.0.1 and Nextcloud Enterprise Server is upgraded to 24.0.12.15, 25.0.13.10, 26.0.13.4, 27.1.10, 28.0.6 or 29.0.1.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-5m5g-hw8c-2236 | Vendor Advisory |
| https://github.com/nextcloud/server/commit/7e1c30f82a63fbea8c269e0eec38291377f32604 | Patch |
| https://github.com/nextcloud/server/pull/45340 | Issue Tracking |
| https://hackerone.com/reports/2484499 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
01 Oct 2025, 18:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-5m5g-hw8c-2236 - Vendor Advisory | |
| References | () https://github.com/nextcloud/server/commit/7e1c30f82a63fbea8c269e0eec38291377f32604 - Patch | |
| References | () https://github.com/nextcloud/server/pull/45340 - Issue Tracking | |
| References | () https://hackerone.com/reports/2484499 - Issue Tracking | |
| CPE | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* |
|
| First Time |
Nextcloud
Nextcloud nextcloud Server |
Information
Published : 2024-11-15 17:15
Updated : 2025-10-01 18:34
NVD link : CVE-2024-52515
Mitre link : CVE-2024-52515
CVE.ORG link : CVE-2024-52515
JSON object : View
Products Affected
nextcloud
- nextcloud_server
CWE
CWE-706
Use of Incorrectly-Resolved Name or Reference
