PT-2014-2443 · Owncloud · Owncloud

Published

2014-03-14

·

Updated

2014-03-26

·

CVE-2013-0298

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ownCloud versions 4.5.x through 4.5.6
Description The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved through various means, including:
  • a crafted iCalendar file to the calendar application,
  • the dir or file parameter to apps/files pdfviewer/viewer.php,
  • the mountpoint parameter to /apps/files external/addMountPoint.php.
Recommendations For ownCloud versions 4.5.x through 4.5.6, update to version 4.5.7 to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0298

Affected Products

Owncloud