CVE Published: 11/06/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: hackerone |
Vendor: n/a |
Product: Nextcloud Mail Status : PUBLISHED
CVE-2021-22896 Description
Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users.