CVE-2013-0301: CSRF
Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 allows remote attackers to hijack the authentication of users for requests that change the timezone via the timezone parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0301?
CVE-2013-0301 is classified as a moderate severity vulnerability due to its potential for cross-site request forgery attacks.
How do I fix CVE-2013-0301?
To fix CVE-2013-0301, upgrade to ownCloud version 4.0.12 or later, which includes patches for this vulnerability.
What software is affected by CVE-2013-0301?
CVE-2013-0301 affects ownCloud versions prior to 4.0.12 and specifically includes versions 3.0.0 to 4.0.11.
What type of vulnerability is CVE-2013-0301?
CVE-2013-0301 is a cross-site request forgery (CSRF) vulnerability that allows attackers to hijack user sessions.
What is the potential impact of CVE-2013-0301?
The potential impact of CVE-2013-0301 includes unauthorized timezone changes by malicious users, compromising user sessions.