PoC Index

CVE-2023-24804

MEDIUM 5.0EPSS 0.5%

The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the app has an incomplete fix for a path traversal issue and is vulnerable to two bypass methods. The bypasses may lead to information disclosure when uploading the app’s internal files, and to arbitrary file write when uploading plain text files (although limited by the .txt extension). Version 3.0 fixes the reported bypasses.

CVSS v3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v3.1
5.0 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.52% chance of exploitation in the next 30 days, 42th percentile
Published
2023-02-13
Updated
2025-03-10

Proof-of-concept exploits (1)

References

Related