CVE-2014-3836

owncloud < 6.0.3 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud Server before 6.0.3 allow remote attackers to hijack the authentication of users for requests that (1) conduct cross-site scripting (XSS) attacks, (2) modify files, or (3) rename files via unspecified vectors.

References (1)

Core 1
Core References

Scores

EPSS 0.0016
EPSS Percentile 36.5%

Details

CWE
CWE-352
Status published
Products (3)
owncloud/owncloud < 6.0.2
owncloud/owncloud_server 6.0.0
owncloud/owncloud_server 6.0.1
Published Jun 04, 2014
Tracked Since Feb 18, 2026