CVE-2013-0307

ownCloud < 4.0.12 and 4.5.x < 4.5.7 - Authenticated Cross-Site Scripting via Group Input Field

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.

References (1)

Core 1
Core References

Scores

EPSS 0.0033
EPSS Percentile 56.2%

Details

CWE
CWE-79
Status published
Products (23)
owncloud/owncloud < 4.0.11
owncloud/owncloud_server 3.0.0
owncloud/owncloud_server 3.0.1
owncloud/owncloud_server 3.0.2
owncloud/owncloud_server 3.0.3
owncloud/owncloud_server 4.0.0
owncloud/owncloud_server 4.0.1
owncloud/owncloud_server 4.0.2
owncloud/owncloud_server 4.0.3
owncloud/owncloud_server 4.0.4
... and 13 more
Published Mar 14, 2014
Tracked Since Feb 18, 2026