CVE-2013-1963

owncloud < 4.5.10 and 5.x < 5.0.5 - Authenticated Unauthorized Contact Download

Title source: llm
STIX 2.1

Description

The contacts application in ownCloud before 4.5.10 and 5.x before 5.0.5 does not properly check the ownership of contacts, which allows remote authenticated users to download arbitrary contacts via unspecified vectors.

References (1)

Core 1
Core References

Scores

EPSS 0.0018
EPSS Percentile 38.7%

Details

CWE
CWE-264
Status published
Products (15)
owncloud/owncloud < 4.5.9
owncloud/owncloud_server 4.5.0
owncloud/owncloud_server 4.5.1
owncloud/owncloud_server 4.5.2
owncloud/owncloud_server 4.5.3
owncloud/owncloud_server 4.5.4
owncloud/owncloud_server 4.5.5
owncloud/owncloud_server 4.5.6
owncloud/owncloud_server 4.5.7
owncloud/owncloud_server 4.5.8
... and 5 more
Published Mar 14, 2014
Tracked Since Feb 18, 2026