Back to search
CVE-2016-9462
Published: Mar 28, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thus a user with read-only access was able to restore old versions.
| Vendor | Product | Versions |
|---|---|---|
n/a | Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 | affected Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 |
Weaknesses (CWE)
References
https://owncloud.org/security/advisory/?id=oc-sa-2016-015
x_refsource_MISC
97285
vdb-entry
x_refsource_BID
https://hackerone.com/reports/146067
x_refsource_MISC
https://nextcloud.com/security/advisory/?id=nc-sa-2016-005
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now