CVE-2019-25337: OwnCloud 8.1.8 - Username Disclosure
OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25337?
CVE-2019-25337 has been classified as a medium severity vulnerability due to its potential for user account enumeration.
How can I fix CVE-2019-25337?
To fix CVE-2019-25337, upgrade to a patched version of OwnCloud that addresses the username enumeration issue.
What is CVE-2019-25337?
CVE-2019-25337 is a username enumeration vulnerability in OwnCloud 8.1.8 that allows attackers to discover user accounts via the share.php endpoint.
Who is affected by CVE-2019-25337?
Users of OwnCloud version 8.1.8 are affected by CVE-2019-25337 due to the vulnerable share.php functionality.
How does CVE-2019-25337 work?
CVE-2019-25337 works by allowing attackers to send crafted GET requests to the share.php endpoint to enumerate valid usernames.