ownCloud Cross-Site Scripting and Security Bypass Vulnerabilities
Last Update Date:
8 Aug 2013
Release Date:
7 Aug 2013
3812
Views
RISK: Medium Risk
TYPE: Servers - Web Servers
Two vulnerabilities have been identified in ownCloud, which can be exploited by malicious people to conduct cross-site scripting attacks and bypass certain security restrictions.
- An error within "user_webdavauth" can be exploited to bypass authorisation and gain access to otherwise restricted functionality.
- Certain unspecified input is not properly sanitised in "Share Interface" before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Impact
- Cross-Site Scripting
- Security Restriction Bypass
System / Technologies affected
- Versions prior to 5.0.8.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 5.0.8 or later.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with