First published: Tue Feb 09 2021(Updated: )
Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud ownCloud | <10.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28645 is a vulnerability that allows for the deletion of system files when deleting users with certain names.
The risk is higher for systems that allow users to register themselves and have the data directory in the web root.
ownCloud/core versions < 10.6 are affected by CVE-2020-28645.
CVE-2020-28645 has a severity rating of 9.1 (critical).
To fix CVE-2020-28645, update ownCloud/core to a version higher than 10.6.0.