Owncloud

Owncloud

117 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 05.11.2025 00:00:00
  • Zuletzt bearbeitet 06.11.2025 19:45:30

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail...

  • EPSS 0.19%
  • Veröffentlicht 10.11.2022 21:15:11
  • Zuletzt bearbeitet 01.05.2025 14:15:30

The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.

  • EPSS 0.39%
  • Veröffentlicht 09.06.2022 04:15:11
  • Zuletzt bearbeitet 21.11.2024 07:05:02

ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.

  • EPSS 0.31%
  • Veröffentlicht 07.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:48

A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.

  • EPSS 0.17%
  • Veröffentlicht 07.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:48

Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.

  • EPSS 0.26%
  • Veröffentlicht 07.09.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:12:48

The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.

  • EPSS 0.18%
  • Veröffentlicht 07.09.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:12:48

The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 19.02.2021 07:15:13
  • Zuletzt bearbeitet 21.11.2024 04:55:04

An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attac...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 19.02.2021 07:15:13
  • Zuletzt bearbeitet 21.11.2024 04:55:04

An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.

  • EPSS 0.21%
  • Veröffentlicht 19.02.2021 07:15:13
  • Zuletzt bearbeitet 21.11.2024 05:29:09

ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else's access to that share.