CVE-2016-9461
MEDIUMNextcloud Server < 9.0.52 - Improper Access Control
Title source: ruleDescription
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
Scores
CVSS v3
4.3
EPSS
0.0076
EPSS Percentile
73.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-284
CWE-275
Status
published
Affected Products (3)
nextcloud/nextcloud_server
< 9.0.52
owncloud/owncloud
< 9.0.4
n/a/Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4
< Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4
Timeline
Published
Mar 28, 2017
Tracked Since
Feb 18, 2026