Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.8 allow remote authenticated users with administrator privileges to inject arbitrary web script or HTML via the (1) quota parameter to /core/settings/ajax/setquota.php, or remote authenticated users with group admin privileges to inject arbitrary web script or HTML via the (2) group field to settings.php or (3) "share with" field.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Mar 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Owncloud owncloud Server
|
|
CPEs | cpe:2.3:a:owncloud:owncloud:4.5.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:4.5.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:4.5.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:4.5.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:4.5.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:4.5.6:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:4.5.7:*:*:*:*:*:*:* |
cpe:2.3:a:owncloud:owncloud_server:4.5.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:4.5.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:4.5.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:4.5.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:4.5.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:4.5.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:4.5.6:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:4.5.7:*:*:*:*:*:*:* |
Vendors & Products |
Owncloud owncloud
|
Owncloud owncloud Server
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:13:33.210Z
Reserved: 2013-02-19T00:00:00
Link: CVE-2013-1822

No data.

Status : Deferred
Published: 2014-03-14T16:55:04.880
Modified: 2025-04-12T10:46:40.837
Link: CVE-2013-1822

No data.