CVE-2014-3833: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Gallery and (2) core components in ownCloud Server before 5.016 and 6.0.x before 6.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the printunescaped function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3833?
CVE-2014-3833 has multiple cross-site scripting vulnerabilities that could allow remote attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2014-3833?
To fix CVE-2014-3833, upgrade to ownCloud Server version 5.0.16 or 6.0.3 or later.
Which versions of ownCloud are affected by CVE-2014-3833?
CVE-2014-3833 affects ownCloud Server versions before 5.0.16 and 6.0.x before 6.0.3.
What components are affected by CVE-2014-3833?
CVE-2014-3833 affects the Gallery and core components of ownCloud Server.
What is the potential impact of CVE-2014-3833?
The potential impact of CVE-2014-3833 includes unauthorized script execution on users' browsers, leading to possible data theft or session hijacking.