PT-2014-2443 · Owncloud · Owncloud
Publicado
2014-03-14
·
Atualizado
2014-03-26
·
CVE-2013-0298
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ownCloud versions 4.5.x through 4.5.6
Description
The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved through various means, including:
- a crafted iCalendar file to the calendar application,
- the
dirorfileparameter toapps/files pdfviewer/viewer.php, - the
mountpointparameter to/apps/files external/addMountPoint.php.
Recommendations
For ownCloud versions 4.5.x through 4.5.6, update to version 4.5.7 to resolve the issue.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Owncloud