An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://owncloud.org/changelog/server/ | release notes product |
https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=44 | third party advisory exploit |
https://owncloud.com/security-advisories/public-link-password-bypass-via-image-previews/ | vendor advisory |