CVE-2013-2150: XSS
Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and 5.x before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to shared files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2150?
The severity of CVE-2013-2150 is classified as medium, primarily due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2013-2150?
To mitigate CVE-2013-2150, upgrade to ownCloud version 4.5.12 or later, or 5.0.7 or later.
Which versions of ownCloud are affected by CVE-2013-2150?
CVE-2013-2150 affects all ownCloud versions prior to 4.5.12 and 5.x versions before 5.0.7.
What types of attacks can be executed through CVE-2013-2150?
CVE-2013-2150 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web script or HTML.
What is the impact of CVE-2013-2150 on users?
The impact of CVE-2013-2150 includes the potential for attackers to impersonate users and steal sensitive information through malicious scripts.