CVE-2013-0301
Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 allows remote attackers to hijack the authentication of users for requests that change the timezone via the timezone parameter.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0012 (0.1%)
Percentil: 30.1%
EPSS: 2026-05-06
Afecta
owncloud:owncloudowncloud:owncloud_serverDescripción técnica
Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 allows remote attackers to hijack the authentication of users for requests that change the timezone via the timezone parameter.
Publicada: 14/3/2014, 17:55:06
Última modificación: 6/5/2026, 22:30:45