CVE-2012-4752Owncloud vulnerability

3 documents3 sources
Severity
5.0MEDIUMNVD
CNA6.8
EPSS
0.6%
top 29.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 5
Latest updateMay 17

Description

appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edit app configurations via unspecified vectors. NOTE: this can be leveraged by unauthenticated remote attackers using CVE-2012-4393.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDowncloud/owncloud_server9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-hm36-5wqj-h637: appconfig2022-05-17
CVEList
CVE-2012-4752: appconfig2012-09-05
CVE-2012-4752 — Owncloud vulnerability | cvebase