CVE-2023-23948
Published on: Not Yet Published
Last Modified on: 02/21/2023 06:54:00 PM UTC
Certain versions of Owncloud from Owncloud contain the following vulnerability:
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version 3.0, the `filelist` database was deprecated. However, injections affecting `owncloud_database` remain relevant as of version 3.0.
- CVE-2023-23948 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
ownCloud - Android version = <= 3.0
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
GHSL-2022-059_GHSL-2022-060: SQL injection vulnerabilities in Owncloud Android app - CVE-2023-24804, CVE-2023-23948 | GitHub Security Lab | securitylab.github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ow…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Owncloud | Owncloud | All | All | All | All |
- cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:android:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
GHSL-2022-059_GHSL-2022-060: SQL injection vulnerabilities in Owncloud Android app - CVE-2023-24804, CVE-2023-23948 securitylab.github.com/advisories/GHS… | 2023-02-07 20:12:01 |
![]() |
The vuln CVE-2023-23948 has a tweet created 0 days ago and retweeted 11 times. twitter.com/GHSecurityLab/… #pow1rtrtwwcve | 2023-02-08 10:06:00 |
![]() |
CVE-2023-23948 : The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Versi… twitter.com/i/web/status/1… | 2023-02-13 17:03:48 |
![]() |
Potentially Critical CVE Detected! CVE-2023-23948 The ownCloud Android app allows ownCloud users to access, share,… twitter.com/i/web/status/1… | 2023-02-13 17:55:59 |
![]() |
CVE-2023-23948 | 2023-02-13 17:38:54 |