CVE-2017-0883 describes a permission increase vulnerability in Nextcloud Server versions prior to 9.0.55 and 10.0.2. An authenticated attacker with read-only access to shared files or folders could exploit a flaw in the OCS sharing API to re-share these items with elevated permissions, potentially gaining the ability to edit them. This medium-severity vulnerability (CVSS 6.4) has a low attack complexity and does not require user interaction, but only impacts the confidentiality and integrity of affected files. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.54CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* | ||
10.0.2CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:10.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.