ownCloud 'calendar_id' Parameter Security Bypass Vulnerability
BID:59966
Info
ownCloud 'calendar_id' Parameter Security Bypass Vulnerability
| Bugtraq ID: | 59966 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-2043 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2013 12:00AM |
| Updated: | May 07 2015 05:05PM |
| Credit: | Mateusz Goik |
| Vulnerable: |
ownCloud ownCloud 5.0.5 ownCloud ownCloud 5.0.4 ownCloud ownCloud 5.0.3 ownCloud ownCloud 5.0.1 ownCloud ownCloud 5.0 ownCloud ownCloud 4.5.10 ownCloud ownCloud 4.5.9 ownCloud ownCloud 4.5.8 ownCloud ownCloud 4.5.7 ownCloud ownCloud 4.5.2 ownCloud ownCloud 4.5 ownCloud ownCloud 4.5.6 ownCloud ownCloud 4.5.5 |
| Not Vulnerable: |
ownCloud ownCloud 5.0.6 ownCloud ownCloud 4.5.11 |
Discussion
ownCloud 'calendar_id' Parameter Security Bypass Vulnerability
ownCloud is prone to a security-bypass vulnerability .
Attackers can exploit this issue to bypass certain security restrictions to perform unauthorized actions. This may aid in further attacks.
Note: This issue was previously discussed in BID 59875 (ownCloud Multiple Security Vulnerabilities), but has been moved to its own record for better documentation.
ownCloud is prone to a security-bypass vulnerability .
Attackers can exploit this issue to bypass certain security restrictions to perform unauthorized actions. This may aid in further attacks.
Note: This issue was previously discussed in BID 59875 (ownCloud Multiple Security Vulnerabilities), but has been moved to its own record for better documentation.
Exploit / POC
ownCloud 'calendar_id' Parameter Security Bypass Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
References
ownCloud 'calendar_id' Parameter Security Bypass Vulnerability
References:
References:
- ownCloud Homepage (ownCloud)
- Privilege escalation in the calendar application (oC-SA-2013-024) (ownCloud)