Owncloud

Owncloud Server

108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 86.24%
  • Veröffentlicht 21.11.2023 22:15:08
  • Zuletzt bearbeitet 02.04.2025 14:17:25

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-si...

  • EPSS 0.3%
  • Veröffentlicht 20.05.2021 13:15:07
  • Zuletzt bearbeitet 31.03.2025 11:54:18

ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the re...

  • EPSS 0.09%
  • Veröffentlicht 19.02.2021 07:15:13
  • Zuletzt bearbeitet 31.03.2025 11:54:18

ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.

  • EPSS 1.36%
  • Veröffentlicht 17.02.2020 19:15:11
  • Zuletzt bearbeitet 31.03.2025 11:54:18

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary file...

  • EPSS 0.99%
  • Veröffentlicht 11.02.2020 16:15:12
  • Zuletzt bearbeitet 31.03.2025 11:54:18

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

  • EPSS 0.25%
  • Veröffentlicht 23.01.2020 20:15:11
  • Zuletzt bearbeitet 31.03.2025 11:54:18

Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.

  • EPSS 0.4%
  • Veröffentlicht 17.12.2019 18:15:13
  • Zuletzt bearbeitet 31.03.2025 11:54:18

Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.

  • EPSS 0.24%
  • Veröffentlicht 22.11.2019 19:15:11
  • Zuletzt bearbeitet 31.03.2025 11:54:18

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to ap...

  • EPSS 0.11%
  • Veröffentlicht 08.01.2016 21:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.

  • EPSS 0.29%
  • Veröffentlicht 08.01.2016 21:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the...