First published: Fri Nov 22 2019(Updated: )
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud ownCloud | >=4.0.0<4.0.11 | |
ownCloud ownCloud | >=4.5.0<4.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-0202 is medium with a severity value of 6.1.
CVE-2013-0202 affects ownCloud versions 4.5.5, 4.0.10, and earlier.
CVE-2013-0202 is a cross-site scripting (XSS) vulnerability.
An attacker can exploit CVE-2013-0202 by injecting arbitrary web script or HTML using the action parameter to core/ajax/sharing.php.
Please refer to the official ownCloud security advisories for information on available fixes or patches.