CVE-2013-0298: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted iCalendar file to the calendar application, the (2) dir or (3) file parameter to apps/filespdfviewer/viewer.php, or the (4) mountpoint parameter to /apps/filesexternal/addMountPoint.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0298?
CVE-2013-0298 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-0298?
To fix CVE-2013-0298, upgrade ownCloud to version 4.5.7 or later.
Which versions of ownCloud are affected by CVE-2013-0298?
CVE-2013-0298 affects ownCloud versions 4.5.0 through 4.5.6.
What types of attacks can be executed through CVE-2013-0298?
CVE-2013-0298 allows remote attackers to execute arbitrary web scripts via crafted iCalendar files or specific parameters in the PDF viewer.
Is user action required to exploit CVE-2013-0298?
Yes, exploitation of CVE-2013-0298 typically requires a user to open a crafted file or visit a malicious link.