First published: Fri Mar 14 2014(Updated: )
Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud | <=4.0.11 | |
ownCloud | =3.0.0 | |
ownCloud | =3.0.1 | |
ownCloud | =3.0.2 | |
ownCloud | =3.0.3 | |
ownCloud | =4.0.0 | |
ownCloud | =4.0.1 | |
ownCloud | =4.0.2 | |
ownCloud | =4.0.3 | |
ownCloud | =4.0.4 | |
ownCloud | =4.0.5 | |
ownCloud | =4.0.6 | |
ownCloud | =4.0.7 | |
ownCloud | =4.0.8 | |
ownCloud | =4.0.9 | |
ownCloud | =4.0.10 | |
ownCloud | =4.5.0 | |
ownCloud | =4.5.1 | |
ownCloud | =4.5.2 | |
ownCloud | =4.5.3 | |
ownCloud | =4.5.4 | |
ownCloud | =4.5.5 | |
ownCloud | =4.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0307 is classified as a medium severity vulnerability due to its potential impact through cross-site scripting.
To fix CVE-2013-0307, update your ownCloud instance to version 4.0.12 or 4.5.7 or later.
CVE-2013-0307 affects ownCloud versions prior to 4.0.12 and 4.5.x before 4.5.7.
CVE-2013-0307 is a cross-site scripting (XSS) vulnerability.
Remote administrators can exploit CVE-2013-0307 to inject arbitrary web scripts or HTML.