Owncloud vulnerabilities

122 known vulnerabilities affecting owncloud/owncloud.

Total CVEs
122
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH7MEDIUM94LOW14

Vulnerabilities

Page 1 of 7
CVE-2019-25337MEDIUMCVSS 5.3v8.1.82026-02-12
CVE-2019-25337 [MEDIUM] CWE-203 CVE-2019-25337: OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discove OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.
cvelistv5nvd
CVE-2022-43679MEDIUMCVSS 5.3≤ 10.11.02022-11-10
CVE-2022-43679 [MEDIUM] CWE-284 CVE-2022-43679: The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trust The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.
nvd
CVE-2022-31649HIGHCVSS 7.5fixed in 10.10.02022-06-09
CVE-2022-31649 [HIGH] CWE-668 CVE-2022-31649: ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Tra ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
nvd
CVE-2021-35946CRITICALCVSS 9.8fixed in 10.8.02021-09-07
CVE-2021-35946 [CRITICAL] CWE-269 CVE-2021-35946: A receiver of a federated share with access to the database with ownCloud version before 10.8 could A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
nvd
CVE-2021-35948MEDIUMCVSS 5.4fixed in 10.8.02021-09-07
CVE-2021-35948 [MEDIUM] CWE-384 CVE-2021-35948: Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an a Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
nvd
CVE-2021-35949MEDIUMCVSS 5.3fixed in 10.8.02021-09-07
CVE-2021-35949 [MEDIUM] CWE-863 CVE-2021-35949: The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permi The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
nvd
CVE-2021-35947MEDIUMCVSS 5.3fixed in 10.8.02021-09-07
CVE-2021-35947 [MEDIUM] CWE-209 CVE-2021-35947: The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
nvd
CVE-2020-10252HIGHCVSS 8.3fixed in 10.4.02021-02-19
CVE-2020-10252 [HIGH] CWE-918 CVE-2020-10252: An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharin An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.
nvd
CVE-2020-36251MEDIUMCVSS 4.3fixed in 10.3.02021-02-19
CVE-2020-36251 [MEDIUM] CVE-2020-36251: ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a gr ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else's access to that share.
nvd
CVE-2020-10254MEDIUMCVSS 5.9fixed in 10.4.02021-02-19
CVE-2020-10254 [MEDIUM] CWE-287 CVE-2020-10254: An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
nvd
CVE-2020-28645CRITICALCVSS 9.1fixed in 10.6.02021-02-09
CVE-2020-28645 [CRITICAL] CWE-20 CVE-2020-28645: Deleting users with certain names caused system files to be deleted. Risk is higher for systems whic Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.
nvd
CVE-2020-28644MEDIUMCVSS 4.3fixed in 10.6.02021-02-09
CVE-2020-28644 [MEDIUM] CWE-352 CVE-2020-28644: The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
nvd
CVE-2020-16255MEDIUMCVSS 6.1fixed in 10.52021-01-15
CVE-2020-16255 [MEDIUM] CWE-79 CVE-2020-16255: ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.' ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
nvd
CVE-2015-4715MEDIUMCVSS 4.9fixed in 6.0.82020-02-17
CVE-2015-4715 [MEDIUM] CWE-552 CVE-2015-4715: The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x be The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.
nvd
CVE-2014-2052CRITICALCVSS 9.8fixed in 5.0.152020-02-11
CVE-2014-2052 [CRITICAL] CWE-611 CVE-2014-2052: Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attac Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
nvd
CVE-2014-2050MEDIUMCVSS 6.5fixed in 5.0.152020-01-23
CVE-2014-2050 [MEDIUM] CWE-352 CVE-2014-2050: Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6. Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
nvd
CVE-2013-0202MEDIUMCVSS 6.1v4.5.5v4.0.10+1 more2019-12-17
CVE-2013-0202 [MEDIUM] CWE-79 CVE-2013-0202: Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attack Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
cvelistv5nvd
CVE-2013-0203MEDIUMCVSS 5.4≤ 4.0.102019-11-22
CVE-2013-0203 [MEDIUM] CWE-79 CVE-2013-0203: Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow rem Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/ajax/addBookmark.php.
nvd
CVE-2014-2048CRITICALCVSS 9.8fixed in 5.0.152018-03-26
CVE-2014-2048 [CRITICAL] CWE-284 CVE-2014-2048: The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by lev The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.
nvd
CVE-2014-1665MEDIUMCVSS 5.4PoCfixed in 6.0.12018-03-20
CVE-2014-1665 [MEDIUM] CWE-79 CVE-2014-1665: Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
nvdosv