CVE-2012-4393Cross-Site Request Forgery in Owncloud

Severity
6.8MEDIUMNVD
NVD5.0
EPSS
0.2%
top 63.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 5
Latest updateMay 17

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users for requests that use (1) addBookmark.php, (2) delBookmark.php, or (3) editBookmark.php in bookmarks/ajax/; (4) calendar/delete.php, (5) calendar/edit.php, (6) calendar/new.php, (7) calendar/update.php, (8) event/delete.php, (9) event/edit.php, (10) event/move.php, (11) event/new.php, (12) import/import.php, (13) settings/setfirstday.php, (14)

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDowncloud/owncloud_server9 versions+8

Patches

🔴Vulnerability Details

4
GHSA
GHSA-hm36-5wqj-h637: appconfig2022-05-17
GHSA
GHSA-px8g-2xv9-5r45: Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 42022-05-17
CVEList
CVE-2012-4393: Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 42012-09-05
CVEList
CVE-2012-4752: appconfig2012-09-05
CVE-2012-4393 — Cross-Site Request Forgery in Owncloud | cvebase