Upstream information

CVE-2025-66512 at MITRE

Description

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v3 Scores
CVSS detail CNA (GitHub) National Vulnerability Database SUSE
Base Score 5.4 6.1 5.4
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack Vector Network Network Network
Attack Complexity Low Low Low
Privileges Required None None None
User Interaction Required Required Required
Scope Unchanged Changed Unchanged
Confidentiality Impact None Low None
Integrity Impact Low Low Low
Availability Impact Low None Low
CVSSv3 Version 3.1 3.1 3.1
SUSE Bugzilla entry: 1254558 [NEW]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Fri Dec 5 20:02:50 2025
CVE page last modified: Wed Dec 10 13:04:39 2025