{"api_version":"1","generated_at":"2026-07-23T14:02:48+00:00","cve":"CVE-2023-25160","urls":{"html":"https://cve.report/CVE-2023-25160","api":"https://cve.report/api/cve/CVE-2023-25160.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-25160","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-25160"},"summary":{"title":"CVE-2023-25160","description":"Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail 1.12.9 for Nextcloud 21, or Mail 1.11.8 for Nextcloud 20 to receive a patch. No known workarounds are available.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2023-02-13 21:15:00","updated_at":"2023-02-22 21:26:00"},"problem_types":["CWE-639"],"metrics":[],"references":[{"url":"https://github.com/nextcloud/mail/pull/7740","name":"https://github.com/nextcloud/mail/pull/7740","refsource":"MISC","tags":[],"title":"Fix mailbox cache sync scope of current mailbox by ChristophWurst · Pull Request #7740 · nextcloud/mail · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://hackerone.com/reports/1784681","name":"https://hackerone.com/reports/1784681","refsource":"MISC","tags":[],"title":"HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m45f-r5gh-h6cx","name":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m45f-r5gh-h6cx","refsource":"MISC","tags":[],"title":"IDOR Vulnerability in Nextcloud Mail · Advisory · nextcloud/security-advisories · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-25160","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25160","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"25160","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nextcloud","cpe5":"mail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-25160","ASSIGNER":"security-advisories@github.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail 1.12.9 for Nextcloud 21, or Mail 1.11.8 for Nextcloud 20 to receive a patch. No known workarounds are available."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-639: Authorization Bypass Through User-Controlled Key","cweId":"CWE-639"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"nextcloud","product":{"product_data":[{"product_name":"security-advisories","version":{"version_data":[{"version_affected":"=","version_value":"< 1.11.8"},{"version_affected":"=","version_value":">= 1.12.0, < 1.12.9"},{"version_affected":"=","version_value":">= 1.13.0, < 1.14.5"},{"version_affected":"=","version_value":">= 2.0.0, < 2.2.1"}]}}]}}]}},"references":{"reference_data":[{"url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m45f-r5gh-h6cx","refsource":"MISC","name":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m45f-r5gh-h6cx"},{"url":"https://github.com/nextcloud/mail/pull/7740","refsource":"MISC","name":"https://github.com/nextcloud/mail/pull/7740"},{"url":"https://hackerone.com/reports/1784681","refsource":"MISC","name":"https://hackerone.com/reports/1784681"}]},"source":{"advisory":"GHSA-m45f-r5gh-h6cx","discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N","version":"3.1"}]}},"nvd":{"publishedDate":"2023-02-13 21:15:00","lastModifiedDate":"2023-02-22 21:26:00","problem_types":["CWE-639"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*","versionEndExcluding":"1.11.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*","versionStartIncluding":"1.12.0","versionEndExcluding":"1.12.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*","versionStartIncluding":"1.13.0","versionEndExcluding":"1.14.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nextcloud:mail:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}