CVE-2012-4397
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowfields.php or (2)…
Does this matter?
Lower severity and a low EPSS score (1.91%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowfields.php or (2) part.choosecalendar.rowfields.shared.php in apps/calendar/templates/; or (3) unspecified vectors to apps/contacts/lib/vcard.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.91% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- owncloud/owncloud · owncloud/owncloud server
- Source
- secalert@redhat.com
References
- http://owncloud.org/changelog/
- http://www.openwall.com/lists/oss-security/2012/08/11/1
- http://www.openwall.com/lists/oss-security/2012/09/02/2
- https://github.com/owncloud/core/commit/00595351400523168e18a08e3ffa5c3b1e7c1f6eExploit, Patch
- https://github.com/owncloud/core/commit/54a371700554ed21a5cb7db03126b6c95ae4cbd3Patch
- http://owncloud.org/changelog/
- http://www.openwall.com/lists/oss-security/2012/08/11/1
- http://www.openwall.com/lists/oss-security/2012/09/02/2
- https://github.com/owncloud/core/commit/00595351400523168e18a08e3ffa5c3b1e7c1f6eExploit, Patch
- https://github.com/owncloud/core/commit/54a371700554ed21a5cb7db03126b6c95ae4cbd3Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.