CVE Vulnerabilities

CVE-2013-0304

Published: Jun 05, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site request forgery (CSRF) vulnerability, but due to lack of details, it is uncertain what the root cause is.

Affected Software

NameVendorStart VersionEnd Version
OwncloudOwncloud*4.5.6 (including)
Owncloud_serverOwncloud4.5.0 (including)4.5.0 (including)
Owncloud_serverOwncloud4.5.1 (including)4.5.1 (including)
Owncloud_serverOwncloud4.5.2 (including)4.5.2 (including)
Owncloud_serverOwncloud4.5.3 (including)4.5.3 (including)
Owncloud_serverOwncloud4.5.4 (including)4.5.4 (including)
Owncloud_serverOwncloud4.5.5 (including)4.5.5 (including)
OwncloudUbuntuoneiric*
OwncloudUbuntuquantal*
OwncloudUbunturaring*
OwncloudUbuntusaucy*
OwncloudUbuntuupstream*

References