CVE-2016-1501
MEDIUMownCloud Server <8.0.9 & <8.1.4 - Info Disclosure
Title source: llmDescription
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.
Scores
CVSS v3
4.3
EPSS
0.0019
EPSS Percentile
41.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-200
Status
draft
Affected Products (4)
owncloud/owncloud
< 8.0.8
owncloud/owncloud_server
owncloud/owncloud_server
owncloud/owncloud_server
Timeline
Published
Jan 08, 2016
Tracked Since
Feb 18, 2026