Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-49105

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.432
EPSS Ranking 98.7%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
Ransomware Campaign
Unknown
Products affected by CVE-2023-49105


Contact Us

Shodan ® - All rights reserved