vendor:
OwnCloud
by:
Daniel Moreno
3.3
CVSS
MEDIUM
Username Disclosure
200
CWE
Product Name: OwnCloud
Affected Version From: 8.1.8
Affected Version To: 8.1.8
Patch Exists: YES
Related CWE: N/A
CPE: a:owncloud:owncloud:8.1.8
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS
2019
OwnCloud 8.1.8 – Username Disclosure
OwnCloud 8.1.8 is vulnerable to username disclosure. An attacker can intercept the connection with Burp, share a file, typing anything and change the GET parameter to '*search=*'. This will return a JSON with all username informations.
Mitigation:
Upgrade to the latest version of OwnCloud and ensure that all security patches are applied.