ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.
2021-02-19T07:15:13.810
2025-03-31T11:54:18.823
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:A/AC:L/Au:S/C:P/I:N/A:N
5.1
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | owncloud | owncloud_server | < 10.3.1 | Yes |