Vulnerability Description
ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site request forgery (CSRF) vulnerability, but due to lack of details, it is uncertain what the root cause is.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Owncloud | Owncloud | <= 4.5.6 |
| Owncloud | Owncloud Server | 4.5.0 |
Related Weaknesses (CWE)
References
- http://owncloud.org/about/security/advisories/oC-SA-2013-007/Vendor Advisory
- http://securite.intrinsec.com/wp-content/uploads/2013/02/ISEC-V2013-01-v-1.0-Own
- http://owncloud.org/about/security/advisories/oC-SA-2013-007/Vendor Advisory
- http://securite.intrinsec.com/wp-content/uploads/2013/02/ISEC-V2013-01-v-1.0-Own
FAQ
What is CVE-2013-0304?
CVE-2013-0304 is a vulnerability with a CVSS score of 4.0 (MEDIUM). ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. ...
How severe is CVE-2013-0304?
CVE-2013-0304 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-0304?
Check the references section above for vendor advisories and patch information. Affected products include: Owncloud Owncloud, Owncloud Owncloud Server.