An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
- https://hackerone.com/reports/427835
No PoCs found on GitHub currently.