PT-2014-2522 · Owncloud · Owncloud

Published

2014-03-14

·

Updated

2014-03-17

·

CVE-2013-1963

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ownCloud versions prior to 4.5.10 ownCloud versions 5.x prior to 5.0.5
Description The contacts application in ownCloud does not properly check the ownership of contacts. This allows remote authenticated users to download arbitrary contacts via unspecified vectors.
Recommendations For ownCloud versions prior to 4.5.10, update to version 4.5.10 or later. For ownCloud versions 5.x prior to 5.0.5, update to version 5.0.5 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1963

Affected Products

Owncloud