CVE-2023-49105
55Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 11%
from disclosure to weapon14 days
Published on NVDNov 21
1st PoC+14d
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Affected products
n/a · n/apublic PoCs found — 1
githubgithub.com/ambionics/owncloud-exploits★ 38⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.