CVE-2013-0304
Publication date 5 June 2014
Last updated 24 July 2024
Ubuntu priority
Description
ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site request forgery (CSRF) vulnerability, but due to lack of details, it is uncertain what the root cause is.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| owncloud | ||
| 14.04 LTS trusty | Not in release | |