Back to Database
Status published
Low
CVE-2023-33184
Blind SSRF in the Nextcloud Mail app on avatar endpoint
Vulnerability Description
Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-33184
Credits & Attribution
No credits recorded in the NVD database.
References
More from nextcloud
View All →CVE-2025-66558
Nextcloud Twofactor WebAuthn app was updated based on public key
Low
3.1
CVE-2025-66557
Nextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-owners
Medium
5.4
CVE-2025-66556
Nextcloud talk allows participants to blindly delete poll drafts of other users by ID
Low
3.5
CVE-2025-66554
Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field
Low
3.5
CVE-2025-66553
Nextcloud Tables app allowed users to view columns metadata information of any table
Medium
4.3
Affected Vendor
nextcloud
View all reports →Affected Software
security-advisories
Vulnerable Versions:
< 1.15.3, < 2.2.5, < 3.02
Timeline
Official Publish:
May 27th, 2023
Last Modified:
January 14th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N