Unrated severityNVD Advisory· Published Feb 4, 2015· Updated Jun 17, 2026
CVE-2014-9041
CVE-2014-9041
Description
The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF tokens, which allow remote attackers to conduct CSRF attacks.
Affected products
29cpe:2.3:a:owncloud:owncloud_server:5.0.0:*:*:*:*:*:*:*+ 27 more
- cpe:2.3:a:owncloud:owncloud_server:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.14:a:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:5.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:6.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:6.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:6.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:6.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:owncloud:owncloud_server:7.0.2:*:*:*:*:*:*:*
- (no CPE)range: <5.0.18 || (>=6.0.0 <6.0.6) || (>=7.0.0 <7.0.3)
Patches
Vulnerability mechanics
References
1- owncloud.org/security/advisory/nvdVendor Advisory
News mentions
0No linked articles in our index yet.