CVE-2016-1498: XSS
Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1498?
CVE-2016-1498 is classified as a Medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-1498?
To fix CVE-2016-1498, upgrade to ownCloud Server version 7.0.12, 8.0.10, 8.1.5, or 8.2.2 or later.
What versions of ownCloud are affected by CVE-2016-1498?
The affected versions are ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2.
Can CVE-2016-1498 be exploited remotely?
Yes, CVE-2016-1498 can be exploited remotely to inject arbitrary web scripts or HTML.
What component of ownCloud is vulnerable in CVE-2016-1498?
CVE-2016-1498 affects the OCS discovery provider component in ownCloud Server.