CVE-2013-0307

EUVD-2013-0325
Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
owncloudowncloud
𝑥
≤ 4.0.11
owncloudowncloud_server
3.0.0
owncloudowncloud_server
3.0.1
owncloudowncloud_server
3.0.2
owncloudowncloud_server
3.0.3
owncloudowncloud_server
4.0.0
owncloudowncloud_server
4.0.1
owncloudowncloud_server
4.0.2
owncloudowncloud_server
4.0.3
owncloudowncloud_server
4.0.4
owncloudowncloud_server
4.0.5
owncloudowncloud_server
4.0.6
owncloudowncloud_server
4.0.7
owncloudowncloud_server
4.0.8
owncloudowncloud_server
4.0.9
owncloudowncloud_server
4.0.10
owncloudowncloud_server
4.5.0
owncloudowncloud_server
4.5.1
owncloudowncloud_server
4.5.2
owncloudowncloud_server
4.5.3
owncloudowncloud_server
4.5.4
owncloudowncloud_server
4.5.5
owncloudowncloud_server
4.5.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
hardy
dne
lucid
dne
oneiric
ignored
precise
not-affected
quantal
ignored
raring
not-affected
saucy
not-affected
trusty
dne
utopic
dne
vivid
dne
wily
dne