ZeroHour

CVE-2020-28645

CVSS 3.1
9.1 critical
EPSS
1%p67
Published
()
Modified
Description

Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.

Vendors
owncloud
Products
owncloud
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.