CVE-2022-24838 is a critical SMTP command injection vulnerability affecting Nextcloud Calendar versions prior to 3.2.2. An unauthenticated attacker can exploit unsanitized newlines in the email value of JSON requests to inject arbitrary SMTP commands, potentially leading to full compromise of confidentiality, integrity, and availability. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. While there are no known public exploits, Metasploit modules, or Nuclei templates, and no evidence of active exploitation or significant community discussion, immediate upgrade to Nextcloud Calendar 3.2.2 is strongly recommended as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.2CPE matchmatch criteria | cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.