Nextcloud Forms
cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:*:*
- >= 4.3.0, < 5.2.7
A vulnerability in the Nextcloud Forms application, affecting versions 4.3.0 through prior to 5.2.7, allows removed collaborators to retain unauthorized read access to respondent files uploaded for forms where they previously had access to results. This issue arises because the file shares are not properly revoked when a collaborator is removed, leaving a gap in file access control.
The vulnerability could lead to unauthorized access to sensitive respondent files, potentially exposing private information.
Users are advised to upgrade the Nextcloud Forms app to version 5.2.7. Alternatively, the Forms app can be disabled.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.