Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-52508— Nextcloud Mail auto configurator can be tricked into sending account information to wrong servers

Quick assessment

Affected
nextcloud security-advisories
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nextcloud Mail是德国Nextcloud公司的一个电子邮件。 Nextcloud Mail存在信息泄露漏洞。攻击者利用该漏洞注册autoconfig.tld,则使用的电子邮件详细信息将发送到攻击者的服务器。

CVSS 8.2 · High EPSS 0.71% · P51

Possible ATT&CK Techniques 1 AI

T1537 · Transfer Data to Cloud Account
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-52508

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nextcloud Mail auto configurator can be tricked into sending account information to wrong servers
Source: CVE Program / CVE List V5
Vulnerability Description
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an email address like user@example.tld that does not support auto configuration, and an attacker managed to register autoconfig.tld, the used email details would be send to the server of the attacker. It is recommended that the Nextcloud Mail app is upgraded to 1.14.6, 1.15.4, 2.2.11, 3.6.3, 3.7.7 or 4.0.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Nextcloud Mail 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Nextcloud Mail是德国Nextcloud公司的一个电子邮件。 Nextcloud Mail存在信息泄露漏洞。攻击者利用该漏洞注册autoconfig.tld,则使用的电子邮件详细信息将发送到攻击者的服务器。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
nextcloud security-advisories >= 1.9.0, < 1.14.6 -

II. Public POCs for CVE-2024-52508

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7572 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2024-52508

登录查看更多情报信息。

Patches & Fixes for CVE-2024-52508 (1)

News Coverage for CVE-2024-52508 (1)

Same Patch Batch · nextcloud · 2024-11-15 · 17 CVEs total

CVE-2024-52511 6.3 MEDIUM Nextcloud Tables has an Authorization Bypass Through User-Controlled Key in Tables
CVE-2024-52515 5.7 MEDIUM Nextcloud Server has incomplete sanitization of SVG files allows to embed other images int
CVE-2024-52520 5.7 MEDIUM Nextcloud Server's link reference provider can be tricked into downloading bigger files th
CVE-2024-52517 4.6 MEDIUM Nextcloud Server's global credentials of external storages are sent back to the frontend
CVE-2024-52523 4.6 MEDIUM Nextcloud Server Custom defined credentials of external storages are sent back to the fron
CVE-2024-52518 4.4 MEDIUM Nextcloud Server is missing password confirmation when changing external storage options
CVE-2024-52510 4.2 MEDIUM Nextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signatur
CVE-2024-52514 4.1 MEDIUM Nextcloud Server allows users to copy folder that contain files that are blocked by the fi
CVE-2024-52509 3.5 LOW Nextcloud Mail app does not respect download permissions in shares
CVE-2024-52507 3.5 LOW Share information of the Nextcloud Tables app is not limited to affected users
CVE-2024-52512 3.3 LOW Nextcloud User OIDC has an open redirection when logging in with User OIDC
CVE-2024-52516 3.0 LOW Nextcloud Server's shares are not removed when user is limited to share with in their grou
CVE-2024-52519 2.7 LOW Nextcloud Server's OAuth2 client secrets were stored in a recoverable way
CVE-2024-52513 2.6 LOW Nextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Pass
CVE-2024-52521 2.6 LOW Nextcloud Server has a potential hash collision for background jobs could skip queuing the
CVE-2024-52525 1.8 LOW Nextcloud Server User password is available in memory of the PHP process

IV. Related Vulnerabilities

V. Comments for CVE-2024-52508

No comments yet


Leave a comment