CVE-2023-45660: Nextcloud Mail
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, target and cookies allows for an attacker to abuse the proxy endpoint to denial of service a third server. It is recommended that the Nextcloud Mail is upgraded to 2.2.8 or 3.3.0. There are no known workarounds for this vulnerability.
Affected products
- Nextcloud Mail: from 2.2.0, before 2.2.8 (fixed in 2.2.8); from 3.0.0, before 3.3.0 (fixed in 3.3.0)
Published 2023-10-16. Last modified 2026-06-17.