CVE-2014-9041

The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF tokens, which allow remote attackers to conduct CSRF attacks.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
owncloudowncloud
𝑥
≤ 5.0.17
owncloudowncloud_server
5.0.0
owncloudowncloud_server
5.0.1
owncloudowncloud_server
5.0.2
owncloudowncloud_server
5.0.3
owncloudowncloud_server
5.0.4
owncloudowncloud_server
5.0.5
owncloudowncloud_server
5.0.6
owncloudowncloud_server
5.0.7
owncloudowncloud_server
5.0.8
owncloudowncloud_server
5.0.9
owncloudowncloud_server
5.0.10
owncloudowncloud_server
5.0.11
owncloudowncloud_server
5.0.12
owncloudowncloud_server
5.0.13
owncloudowncloud_server
5.0.14
owncloudowncloud_server
5.0.14:a
owncloudowncloud_server
5.0.15
owncloudowncloud_server
5.0.16
owncloudowncloud_server
6.0.0
owncloudowncloud_server
6.0.1
owncloudowncloud_server
6.0.2
owncloudowncloud_server
6.0.3
owncloudowncloud_server
6.0.4
owncloudowncloud_server
6.0.5
owncloudowncloud_server
7.0.0
owncloudowncloud_server
7.0.1
owncloudowncloud_server
7.0.2
𝑥
= Vulnerable software versions