关键漏洞信息 漏洞标题 Bypass group folder quota limit using attachment in text file 严重性 Moderate CVSS v3 base metrics: 4.3/10 影响范围 Package: Enterprise Server (Nextcloud), Groupfolders (Nextcloud), Server (Nextcloud) Affected versions: - Enterprise Server: >= 30.0.0, >= 29.0.0, >= 28.0.0 - Groupfolders: >= 18.0.0, >= 17.0.0, >= 16.0.0 - Server: >= 30.0.0, >= 29.0.0 Patched versions: - Enterprise Server: 30.0.2, 29.0.9, 28.0.12 - Groupfolders: 18.0.3, 17.0.5, 16.0.11 - Server: 30.0.2, 29.0.9 描述与影响 Impact: The absence of quota checking on attachments allowed logged-in users to upload files exceeding the group folder quota. 修复建议 Patches: - Nextcloud Server: Upgrade to 30.0.2 or 29.0.9 - Nextcloud Enterprise Server: Upgrade to 30.0.2, 29.0.9, or 28.0.12 - Nextcloud Groupfolders app: Upgrade to 18.0.3, 17.0.5, or 16.0.11 其他信息 CVE ID: CVE-2025-47793 Weaknesses: CWE-770 References: - HackerOne - PullRequest - PullRequest