CVE-2024-52511

Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*

History

01 Oct 2025, 18:06

Type Values Removed Values Added
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4qqp-9h2g-7qg7 - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4qqp-9h2g-7qg7 - Vendor Advisory
References () https://github.com/nextcloud/tables/commit/52846ad81fe192ee977f14c82a229b0d9cdc406c - () https://github.com/nextcloud/tables/commit/52846ad81fe192ee977f14c82a229b0d9cdc406c - Patch
References () https://github.com/nextcloud/tables/pull/1351 - () https://github.com/nextcloud/tables/pull/1351 - Issue Tracking
References () https://hackerone.com/reports/2671404 - () https://hackerone.com/reports/2671404 - Issue Tracking
CPE cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*
First Time Nextcloud tables
Nextcloud

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) Nextcloud Tables permite a los usuarios crear tablas con columnas individuales. Al especificar directamente el ID de una tabla o vista, un usuario malintencionado podría insertar ciegamente nuevas filas en tablas a las que no tiene acceso. Se recomienda actualizar Nextcloud Tables a la versión 0.8.0.

15 Nov 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 18:15

Updated : 2025-10-01 18:06


NVD link : CVE-2024-52511

Mitre link : CVE-2024-52511

CVE.ORG link : CVE-2024-52511


JSON object : View

Products Affected

nextcloud

  • tables
CWE
CWE-639

Authorization Bypass Through User-Controlled Key