{"id":"CVE-2025-66546","summary":"Nextcloud Calendar app allowed booking appointments without the generated token","details":"Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.","aliases":["GHSA-7x2j-2674-fj95"],"modified":"2026-08-12T03:51:27.113781920Z","published":"2025-12-05T16:49:46.553Z","database_specific":{"cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66546.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3275810"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66546.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7x2j-2674-fj95"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66546"},{"type":"FIX","url":"https://github.com/nextcloud/calendar/commit/f41650c3681fc4a4130eb883f5c0899c011326b3"},{"type":"FIX","url":"https://github.com/nextcloud/calendar/pull/7537"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/calendar","events":[{"introduced":"d840d46412d121c9ae2697efed7f1ce6dd414fc2"},{"fixed":"ee0fc1397f2cbade31712e17cabe7fd4503d3a32"},{"introduced":"31203fddf125223d25f3b8b0d520f567a998e8af"},{"fixed":"dfb76536948a4829539a61aaaa4d939afd743cb5"},{"introduced":"d8566e7d4dffaec2a2c4a3adcdb0be9dab2556ba"},{"fixed":"f41650c3681fc4a4130eb883f5c0899c011326b3"}],"database_specific":{"cpe":["cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*","cpe:2.3:a:nextcloud:calendar:6.0.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.7.19"},{"introduced":"5.0.0"},{"fixed":"5.5.6"},{"introduced":"6.0.0-NA"},{"last_affected":"6.0.0-NA"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["6.0.0-NA"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66546.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}