CVE-2013-2086

owncloud_server - Exposure of Sensitive Information via JavaScript File

Title source: llm
STIX 2.1

Description

The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an unspecified JavaScript file.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
http://owncloud.org/about/security/advisories/oC-SA-2013-027/

Scores

EPSS 0.0025
EPSS Percentile 48.3%

Details

CWE
CWE-200
Status published
Products (6)
owncloud/owncloud_server 5.0.0
owncloud/owncloud_server 5.0.1
owncloud/owncloud_server 5.0.2
owncloud/owncloud_server 5.0.3
owncloud/owncloud_server 5.0.4
owncloud/owncloud_server 5.0.5
Published Mar 14, 2014
Tracked Since Feb 18, 2026