CVE-2014-2047Improper Authentication in Owncloud

Severity
6.8MEDIUMNVD
EPSS
0.4%
top 41.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 17

Description

Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9hf4-63r7-m7v7: Session fixation vulnerability in ownCloud before 62022-05-17
CVEList
CVE-2014-2047: Session fixation vulnerability in ownCloud before 62014-03-14
CVE-2014-2047 — Improper Authentication in Owncloud | cvebase