Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HOwncloud
APPOwncloud< 10.6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-35946CRITICAL9.8PL ✓same product
ownCloud: privilege escalation przez modyfikację uprawnień federated share
CVE-2014-2052CRITICAL9.8PL ✓same product
XXE w Zend Framework umożliwia odczyt plików w ownCloud Server
CVE-2014-2048CRITICAL9.8PL ✓same product
ownCloud: niezabezpieczona implementacja OpenID umożliwia nieautoryzowany dostęp
CVE-2022-31649HIGH7.5same product
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
CVE-2020-10252HIGH8.3same product
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external...