CVE-2013-0304

owncloud < 4.5.7 - Authenticated Arbitrary Calendar Read via calid Parameter

Title source: llm
STIX 2.1

Description

ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site request forgery (CSRF) vulnerability, but due to lack of details, it is uncertain what the root cause is.

Scores

EPSS 0.0028
EPSS Percentile 51.8%

Details

CWE
CWE-264
Status published
Products (7)
owncloud/owncloud < 4.5.6
owncloud/owncloud_server 4.5.0
owncloud/owncloud_server 4.5.1
owncloud/owncloud_server 4.5.2
owncloud/owncloud_server 4.5.3
owncloud/owncloud_server 4.5.4
owncloud/owncloud_server 4.5.5
Published Jun 05, 2014
Tracked Since Feb 18, 2026