CVE-2013-0297: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) sitename or (2) siteurl parameter to apps/external/ajax/setsites.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0297?
CVE-2013-0297 has a moderate severity rating due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2013-0297?
To fix CVE-2013-0297, you should update your ownCloud installation to version 4.0.12 or 4.5.7 or later.
What types of vulnerabilities are associated with CVE-2013-0297?
CVE-2013-0297 is associated with multiple cross-site scripting (XSS) vulnerabilities.
Which versions of ownCloud are affected by CVE-2013-0297?
CVE-2013-0297 affects ownCloud versions prior to 4.0.12 and 4.5.x before 4.5.7.
Can CVE-2013-0297 be exploited by remote authenticated administrators?
Yes, CVE-2013-0297 can be exploited by remote authenticated administrators to inject arbitrary web scripts or HTML.