Unrated severityNVD Advisory· Published May 8, 2015· Updated May 6, 2026
CVE-2015-3012
CVE-2015-3012
Description
Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, allow remote attackers to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) javascript or (4) data URI.
Affected products
2- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/kogmbh/WebODF/blob/master/ChangeLog.mdnvdPatchVendor Advisory
- github.com/kogmbh/WebODF/pull/849nvdPatch
- github.com/kogmbh/WebODF/pull/850/filesnvdPatch
- www.debian.org/security/2015/dsa-3244nvdVendor Advisory
- www.securityfocus.com/bid/74445nvdThird Party AdvisoryVDB Entry
- owncloud.org/security/advisory/nvdVendor Advisory
News mentions
0No linked articles in our index yet.