CVE-2022-24838
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
11/04/2022
Last modified:
23/06/2023
Description
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out of the `RCPT TO: ` SMTP command and begin injecting arbitrary SMTP commands. It is recommended that Calendar is upgraded to 3.2.2. There are no workaround available.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:* | 3.2.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



