Skip to main content

CVE-2022-31132

8.3
HIGHCVSS v3.1 Base Score
0.42%
LOW RiskEPSS (62nd percentile)

Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS minifier on the path `./vendor/cerdic/css-tidy/css_optimiser.php`. Access to the minifier is unrestricted and access may lead to Server-Side Request Forgery (SSRF). It is recommendet to upgrade to Mail 1.12.7 or Mail 1.13.6. Users unable to upgrade may manually delete the file located at `./vendor/cerdic/css-tidy/css_optimiser.php`

Published: 8/4/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

EPSS Score (Exploitation Probability)

0.42%LOW Exploitation Risk
62nd percentile

This vulnerability has a 0.42% probability of being exploited in the next 30 days, ranking higher than 62% of all scored CVEs.

Related Vulnerabilities