ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://owncloud.org/security/advisories/ | broken link |
https://owncloud.com/security-advisories/reflected-xss-in-login-page-forgot-password-functionallity/ | vendor advisory |