Insecure Direct Object Reference in Nextcloud Server
CVE-2025-64011
4.3MEDIUM
What is CVE-2025-64011?
Nextcloud Server version 30.0.0 offers a security risk through an Insecure Direct Object Reference within the /core/preview endpoint. Authenticated users can exploit this vulnerability by altering the fileId parameter, gaining access to file previews belonging to other users without appropriate permission. This flaw facilitates unauthorized data exposure, potentially revealing sensitive information such as documents and images, creating significant privacy and security concerns.