THREATOPS
THREAT OPSThreat News › [NVD] CVE-2023-49105 (CRITICAL 9.8) — An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even

[NVD] CVE-2023-49105 (CRITICAL 9.8) — An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even

lownvdPublished 2023-11-21

CVE-2023-49105 CVSS: 9.8 CRITICAL Published: 2023-11-21T22:15:08.613

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner o

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-49105