CVE-2013-1963Owncloud vulnerability

CWE-2645 documents5 sources
Severity
4.0MEDIUMNVD
EPSS
0.2%
top 60.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 17

Description

The contacts application in ownCloud before 4.5.10 and 5.x before 5.0.5 does not properly check the ownership of contacts, which allows remote authenticated users to download arbitrary contacts via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages3 packages

Ubuntuowncloud/owncloud< 6.0.1+dfsg-1ubuntu1
NVDowncloud/owncloud_server14 versions+13

🔴Vulnerability Details

3
GHSA
GHSA-m87h-45p6-6c2q: The contacts application in ownCloud before 42022-05-17
CVEList
CVE-2013-1963: The contacts application in ownCloud before 42014-03-14
OSV
CVE-2013-1963: The contacts application in ownCloud before 42014-03-14

💬Community

1
Bugzilla
CVE-2013-1963 CVE-2013-1967 owncloud: security fixes in 4.5.102013-04-22
CVE-2013-1963 — Owncloud vulnerability | cvebase