PublicCVE

CVE-2023-49105

CRITICAL9.8Auth bypass
CISA KEVPublic PoC

Description

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

CVSS breakdown

CVSS 3.1
Attack Complexity
Low
Attack Vector
Network
Availability
High
Confidentiality
High
Integrity
High
Privileges Required
None
Scope
Unchanged
User Interaction
None

Exploits & proofs of concept

Updated 24m ago · 8 sources