CVE-2014-9041
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF tokens, which allow remote attackers to conduct CSRF attacks.
La funcionalidad de importaciĆ³n en la aplicaciĆ³n bookmarks application en el servidor ownCloud anterior a 5.0.18, 6.x anterior a 6.0.6, y 7.x anterior a 7.0.3 no valida los tokens CSRF, lo que permiten a atacantes remotos realizar ataques de CSRF.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-11-21 CVE Reserved
- 2015-02-04 CVE Published
- 2023-06-10 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://owncloud.org/security/advisory/?id=oc-sa-2014-027 | 2015-02-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | <= 5.0.17 Search vendor "Owncloud" for product "Owncloud" and version " <= 5.0.17" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.0 Search vendor "Owncloud" for product "Owncloud" and version "5.0.0" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.1 Search vendor "Owncloud" for product "Owncloud" and version "5.0.1" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.2 Search vendor "Owncloud" for product "Owncloud" and version "5.0.2" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.3 Search vendor "Owncloud" for product "Owncloud" and version "5.0.3" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.4 Search vendor "Owncloud" for product "Owncloud" and version "5.0.4" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.5 Search vendor "Owncloud" for product "Owncloud" and version "5.0.5" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.6 Search vendor "Owncloud" for product "Owncloud" and version "5.0.6" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.7 Search vendor "Owncloud" for product "Owncloud" and version "5.0.7" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.8 Search vendor "Owncloud" for product "Owncloud" and version "5.0.8" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.9 Search vendor "Owncloud" for product "Owncloud" and version "5.0.9" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.10 Search vendor "Owncloud" for product "Owncloud" and version "5.0.10" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.11 Search vendor "Owncloud" for product "Owncloud" and version "5.0.11" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.12 Search vendor "Owncloud" for product "Owncloud" and version "5.0.12" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.13 Search vendor "Owncloud" for product "Owncloud" and version "5.0.13" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.14 Search vendor "Owncloud" for product "Owncloud" and version "5.0.14" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.14 Search vendor "Owncloud" for product "Owncloud" and version "5.0.14" | a |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.15 Search vendor "Owncloud" for product "Owncloud" and version "5.0.15" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 5.0.16 Search vendor "Owncloud" for product "Owncloud" and version "5.0.16" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 6.0.0 Search vendor "Owncloud" for product "Owncloud" and version "6.0.0" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 6.0.1 Search vendor "Owncloud" for product "Owncloud" and version "6.0.1" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 6.0.2 Search vendor "Owncloud" for product "Owncloud" and version "6.0.2" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 6.0.3 Search vendor "Owncloud" for product "Owncloud" and version "6.0.3" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 6.0.4 Search vendor "Owncloud" for product "Owncloud" and version "6.0.4" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 6.0.5 Search vendor "Owncloud" for product "Owncloud" and version "6.0.5" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 7.0.0 Search vendor "Owncloud" for product "Owncloud" and version "7.0.0" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 7.0.1 Search vendor "Owncloud" for product "Owncloud" and version "7.0.1" | - |
Affected
| ||||||
Owncloud Search vendor "Owncloud" | Owncloud Search vendor "Owncloud" for product "Owncloud" | 7.0.2 Search vendor "Owncloud" for product "Owncloud" and version "7.0.2" | - |
Affected
|