CVE-2012-4396: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file names to apps/userldap/settings.php; (2) url or (3) title parameter to apps/bookmarks/ajax/editBookmark.php; (4) tag or (5) page parameter to apps/bookmarks/ajax/updateList.php; (6) identity to apps/useropenid/settings.php; (7) stack name in apps/gallery/lib/tiles.php; (8) root parameter to apps/gallery/templates/index.php; (9) calendar displayname in apps/calendar/templates/part.import.php; (10) calendar uri in apps/calendar/templates/part.choosecalendar.rowfields.php; (11) title, (12) location, or (13) description parameter in apps/calendar/lib/object.php; (14) certain vectors in core/js/multiselect.js; or (15) artist, (16) album, or (17) title comments parameter in apps/media/libscanner.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4396?
CVE-2012-4396 has been recognized as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2012-4396?
To fix CVE-2012-4396, you should upgrade ownCloud to version 4.0.2 or later to mitigate the vulnerabilities.
Which versions are affected by CVE-2012-4396?
CVE-2012-4396 affects ownCloud versions prior to 4.0.2, including 3.0.0 to 4.0.1.
What kind of attacks can CVE-2012-4396 enable?
CVE-2012-4396 can enable remote attackers to perform cross-site scripting attacks, injecting arbitrary web scripts or HTML.
Is CVE-2012-4396 a common vulnerability?
CVE-2012-4396 is a known vulnerability within the ownCloud ecosystem and can pose a risk if not addressed.