CVE-2016-1501

MEDIUM

ownCloud Server <8.0.9 & <8.1.4 - Info Disclosure

Title source: llm

Description

ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (4)

owncloud/owncloud < 8.0.8
owncloud/owncloud_server
owncloud/owncloud_server
owncloud/owncloud_server

Timeline

Published Jan 08, 2016
Tracked Since Feb 18, 2026