First published: Wed Jun 04 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Gallery and (2) core components in ownCloud Server before 5.016 and 6.0.x before 6.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the print_unescaped function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud | <=5.0.15 | |
ownCloud | =5.0.0 | |
ownCloud | =5.0.1 | |
ownCloud | =5.0.2 | |
ownCloud | =5.0.3 | |
ownCloud | =5.0.4 | |
ownCloud | =5.0.5 | |
ownCloud | =5.0.6 | |
ownCloud | =5.0.7 | |
ownCloud | =5.0.8 | |
ownCloud | =5.0.9 | |
ownCloud | =5.0.10 | |
ownCloud | =5.0.11 | |
ownCloud | =5.0.12 | |
ownCloud | =5.0.13 | |
ownCloud | =5.0.14 | |
ownCloud | =5.0.14-a | |
ownCloud | =6.0.0 | |
ownCloud | =6.0.1 | |
ownCloud | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3833 has multiple cross-site scripting vulnerabilities that could allow remote attackers to inject arbitrary web scripts or HTML.
To fix CVE-2014-3833, upgrade to ownCloud Server version 5.0.16 or 6.0.3 or later.
CVE-2014-3833 affects ownCloud Server versions before 5.0.16 and 6.0.x before 6.0.3.
CVE-2014-3833 affects the Gallery and core components of ownCloud Server.
The potential impact of CVE-2014-3833 includes unauthorized script execution on users' browsers, leading to possible data theft or session hijacking.