CVE-2013-0304 Information
Feb 14, 2021
cve
Description
ownCloud Server before 4.5.7 does not properly check ownership of calendars which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site request forgery (CSRF) vulnerability but due to lack of details it is uncertain what the root cause is.
Reference
http://owncloud.org/about/security/advisories/oC-SA-2013-007/ http://securite.intrinsec.com/wp-content/uploads/2013/02/ISEC-V2013-01-v-1.0-Owncloud-4.5.4-Arbitrary-calendar-export.pdf
Share on: