ownCloud CVE-2013-2040 Multiple Cross Site Scripting Vulnerabilities
BID:59950
Info
ownCloud CVE-2013-2040 Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 59950 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2040 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2013 12:00AM |
| Updated: | Apr 13 2015 10:23PM |
| Credit: | Mateusz Goik |
| Vulnerable: |
ownCloud ownCloud 5.0.5 ownCloud ownCloud 5.0.4 ownCloud ownCloud 5.0.3 ownCloud ownCloud 5.0.1 ownCloud ownCloud 5.0 ownCloud ownCloud 4.5.10 ownCloud ownCloud 4.5.9 ownCloud ownCloud 4.5.8 ownCloud ownCloud 4.5.7 ownCloud ownCloud 4.5.2 ownCloud ownCloud 4.5 ownCloud ownCloud 4.0.14 ownCloud ownCloud 4.0.13 ownCloud ownCloud 4.0.12 ownCloud ownCloud 4.0.9 ownCloud ownCloud 4.0.7 ownCloud ownCloud 4.0.6 ownCloud ownCloud 4.0.5 ownCloud ownCloud 4.0.4 ownCloud ownCloud 4.5.6 ownCloud ownCloud 4.5.5 ownCloud ownCloud 4.0.3 ownCloud ownCloud 4.0.2 ownCloud ownCloud 4.0.11 ownCloud ownCloud 4.0.10 ownCloud ownCloud 4.0.1 ownCloud ownCloud 3.0.2 ownCloud ownCloud 3.0.1 ownCloud ownCloud 3.0.0 |
| Not Vulnerable: |
ownCloud ownCloud 5.0.6 ownCloud ownCloud 4.5.11 ownCloud ownCloud 4.0.15 |
Discussion
ownCloud CVE-2013-2040 Multiple Cross Site Scripting Vulnerabilities
ownCloud is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Note: This issue was previously discussed in BID 59875 (ownCloud Multiple Security Vulnerabilities), but has been moved to its own record for better documentation.
ownCloud versions prior to 4.0.15, 4.5.11 and 5.0.6 are vulnerable.
ownCloud is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Note: This issue was previously discussed in BID 59875 (ownCloud Multiple Security Vulnerabilities), but has been moved to its own record for better documentation.
ownCloud versions prior to 4.0.15, 4.5.11 and 5.0.6 are vulnerable.
Exploit / POC
ownCloud CVE-2013-2040 Multiple Cross Site Scripting Vulnerabilities
An attacker must trick an unsuspecting victim into following a malicious URI to exploit these issues.
An attacker must trick an unsuspecting victim into following a malicious URI to exploit these issues.
Solution / Fix
ownCloud CVE-2013-2040 Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ownCloud CVE-2013-2040 Multiple Cross Site Scripting Vulnerabilities
References:
References:
- ownCloud Homepage (ownCloud)
- Multiple XSS vulnerabilities (oC-SA-2013-021) (ownCloud)