Skip to content

CVE-2013-0307

Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0028 (0.3%)
Percentile: 51.7%
EPSS: 2026-05-06

Affects

owncloud:owncloudowncloud:owncloud_server

Technical description

Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.

Published: 3/14/2014, 3:55:05 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam