Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 12 min 101 bronnen 3 kritiek 7 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2013-2042

LOW · 3.5 CVSS Gepubliceerd: CWE-79

Beschrijving

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the url parameter to (1) apps/bookmarks/ajax/addBookmark.php or (2) apps/bookmarks/ajax/editBookmark.php.

Vendors

Owncloud

Affected products

Owncloud Owncloud Server

References