Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alessandro Groppo

Researcher fromHacktive Security s.r.l.
#50855of 53,630
4.3Total CVSS
Vulnerabilities · 1
PT-2021-11570
4.3
2021-02-09
Owncloud · Owncloud · CVE-2020-28644
Name of the Vulnerable Software and Affected Versions: ownCloud/core versions prior to 10.6 Description: The issue is related to an improper implementation of the CSRF token check on cookie authenticated requests against some ocs API endpoints. Recommendations: For ownCloud/core versions prior to 10.6, update to version 10.6 or later to resolve the issue.