Medium severity4.3NVD Advisory· Published Mar 28, 2017· Updated May 13, 2026
CVE-2016-9461
CVE-2016-9461
Description
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- github.com/nextcloud/server/commit/3491400261c1454a9a30d3ec96969573330120ccnvdIssue TrackingPatchThird Party Advisory
- github.com/owncloud/core/commit/0622e635d97cb17c5e1363e370bb8268cc3d2547nvdIssue TrackingPatchThird Party Advisory
- github.com/owncloud/core/commit/121a3304a0c37ccda0e1b63ddc528cba9121a36envdIssue TrackingPatchThird Party Advisory
- github.com/owncloud/core/commit/acbbadb71ceee7f01da347f7dcd519beda78cc47nvdIssue TrackingPatchThird Party Advisory
- github.com/owncloud/core/commit/c0a4b7b3f38ad2eaf506484b3b92ec678cb021c9nvdIssue TrackingPatchThird Party Advisory
- nextcloud.com/security/advisory/nvdPatchVendor Advisory
- owncloud.org/security/advisory/nvdPatchVendor Advisory
- hackerone.com/reports/145950nvdExploitThird Party Advisory
- www.securityfocus.com/bid/97276nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.