CVE-2022-24838

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
11/04/2022
Last modified:
23/06/2023

Description

Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out of the `RCPT TO: ` SMTP command and begin injecting arbitrary SMTP commands. It is recommended that Calendar is upgraded to 3.2.2. There are no workaround available.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:* 3.2.2 (excluding)