VYPR
Medium severity6.1NVD Advisory· Published Dec 17, 2019· Updated Jun 16, 2026

CVE-2013-0202

CVE-2013-0202

Description

Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.

Affected products

3
  • cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*
    Range: >=4.0.0,<4.0.11
  • OwnCloud/Owncloudllm-fuzzy2 versions
    <=4.5.5, <=4.0.10+ 1 more
    • (no CPE)range: <=4.5.5, <=4.0.10
    • (no CPE)range: 4.5.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.