CVE-2016-9462
MEDIUMNextcloud Server < 9.0.52 - Improper Access Control
Title source: ruleDescription
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thus a user with read-only access was able to restore old versions.
Scores
CVSS v3
4.3
EPSS
0.0046
EPSS Percentile
63.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-284
CWE-275
Status
published
Affected Products (3)
nextcloud/nextcloud_server
< 9.0.52
owncloud/owncloud
< 9.0.4
n/a/Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4
< Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4
Timeline
Published
Mar 28, 2017
Tracked Since
Feb 18, 2026