First published: Fri Nov 22 2019(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/ajax/addBookmark.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud ownCloud | <=4.0.10 | |
ownCloud ownCloud | >=4.5.0<=4.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-0203 is medium with a CVSS score of 5.4.
CVE-2013-0203 refers to multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier.
Remote attackers can exploit CVE-2013-0203 by injecting arbitrary web script or HTML via unspecified parameters to certain files in ownCloud.
Yes, ownCloud has released security advisories with fixes for the XSS vulnerabilities in CVE-2013-0203.
The Common Weakness Enumeration (CWE) ID of CVE-2013-0203 is 79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').