CVE Vulnerabilities

CVE-2013-2043

Published: Mar 14, 2014 | Modified: Mar 17, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.

Affected Software

Name Vendor Start Version End Version
Owncloud Owncloud 5.0.2 5.0.2
Owncloud Owncloud * 4.5.10
Owncloud Owncloud 5.0.3 5.0.3
Owncloud Owncloud 4.5.1 4.5.1
Owncloud Owncloud 4.5.7 4.5.7
Owncloud Owncloud 4.5.9 4.5.9
Owncloud Owncloud 5.0.0 5.0.0
Owncloud Owncloud 5.0.1 5.0.1
Owncloud Owncloud 4.5.0 4.5.0
Owncloud Owncloud 5.0.4 5.0.4
Owncloud Owncloud 4.5.2 4.5.2
Owncloud Owncloud 4.5.4 4.5.4
Owncloud Owncloud 4.5.8 4.5.8
Owncloud Owncloud 4.5.3 4.5.3
Owncloud Owncloud 4.5.5 4.5.5
Owncloud Owncloud 4.5.6 4.5.6
Owncloud Owncloud 5.0.5 5.0.5

References