Vulnerabilities > CVE-2020-36252 - Exposure of Resource to Wrong Sphere vulnerability in Owncloud

047910
CVSS 2.7 - LOW
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
low complexity
owncloud
CWE-668

Summary

ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.

Common Weakness Enumeration (CWE)