CVE-2019-25337
CRITICALOwnCloud 8.1.8 - Info Disclosure
Title source: llmDescription
OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0017
EPSS Percentile
37.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-203
Status
published
Products (1)
OwnCloud/OwnCloud
8.1.8
Published
Feb 12, 2026
Tracked Since
Feb 18, 2026