CVE-2013-0202: XSS
Published Nov 22, 2019
·Updated
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
Affected Software
4 affected components
ownCloud ownCloud>=4.0.0<4.0.11
ownCloud ownCloud>=4.5.0<4.5.6
ownCloud ownCloud Server>=4.0.0<4.0.11
ownCloud ownCloud Server>=4.5.0<4.5.6
Event History
Nov 22, 2019
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionWeakness
Dec 17, 2019
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0202?
The severity of CVE-2013-0202 is medium with a severity value of 6.1.
2
How does CVE-2013-0202 affect ownCloud?
CVE-2013-0202 affects ownCloud versions 4.5.5, 4.0.10, and earlier.
3
What is the vulnerability in CVE-2013-0202?
CVE-2013-0202 is a cross-site scripting (XSS) vulnerability.
4
How can an attacker exploit CVE-2013-0202?
An attacker can exploit CVE-2013-0202 by injecting arbitrary web script or HTML using the action parameter to core/ajax/sharing.php.
5
Are there any available fixes or patches for CVE-2013-0202?
Please refer to the official ownCloud security advisories for information on available fixes or patches.