# CVE-2024-37316

## Summary

- **CVE ID:** CVE-2024-37316
- **Severity:** MEDIUM
- **CVSS Score:** 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
- **CWE:** CWE-241
- **Published:** Jun 14, 2024
- **Last Modified:** Mar 13, 2026

## Description

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.

## Affected Products

- nextcloud — security-advisories (>= 4.3.0, < 4.6.8)
- nextcloud — security-advisories (>= 4.7.0, < 4.7.2)

## References

- [CNA](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2r7q-vfmv-79qf)
- [CNA](https://github.com/nextcloud/calendar/pull/5966)
- [CNA](https://hackerone.com/reports/2457588)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.36%
- **EPSS Percentile:** 29.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._