CVE-2020-16255Cross-site Scripting in Owncloud

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 41.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 15
Latest updateMay 24

Description

ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDowncloud/owncloud< 10.5
Alpineruby-lang/ruby< 2.5.8-r0+1

🔴Vulnerability Details

3
GHSA
GHSA-686m-27qq-c25w: ownCloud (Core) before 102022-05-24
CVEList
CVE-2020-16255: ownCloud (Core) before 102021-01-15
OSV
CVE-2020-16255: ownCloud (Core) before 102021-01-15
CVE-2020-16255 — Cross-site Scripting in Owncloud | cvebase