Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
| Software | From | Fixed in |
|---|---|---|
| nextcloud / calendar | 4.0.0 | 4.7.19 |
| nextcloud / calendar | 5.0.0 | 5.5.6 |
| nextcloud / calendar | 6.0.0 | 6.0.0.x |
| nextcloud / calendar | 6.0.0-rc1 | 6.0.0-rc1.x |
| nextcloud / calendar | 6.0.0-rc2 | 6.0.0-rc2.x |
| nextcloud / calendar | 6.0.0-rc3 | 6.0.0-rc3.x |
| nextcloud / calendar | 6.0.0-rc4 | 6.0.0-rc4.x |
| nextcloud / calendar | 6.0.0-rc5 | 6.0.0-rc5.x |
| nextcloud / calendar | 6.0.0-rc6 | 6.0.0-rc6.x |